topicmaker Veteran


Joined: 28 Feb 2006 Posts: 26084
|
Posted: Wed Mar 04, 2026 10:12 am Post subject: Critical Flaw in MS-Agent AI Framework Exposes Systems to Re |
|
|
| The CERT Coordination Center has disclosed VU#431821, a severe command injection vulnerability (CVE-2026-2256) in ModelScope's MS-Agent framework, allowing attackers to execute arbitrary OS commands via crafted prompt inputs. The flaw affects the Shell tool, where unsanitized user-derived content bypasses fragile denylist filte...read more |
|