Critical CVE-2026-2256: MS-Agent Shell Tool Vulnerability Enables Remote Code Execution.
Mar 3, 2026 // 14:26 - Lina Schonbein


A critical vulnerability, tracked as CVE-2026-2256, has been identified in the ModelScope MS-Agent framework (an open-source AI agent framework), which can lead to a full system compromise. 

  • The Flaw: The vulnerability exists in the framework’s Shell tool, which allows AI agents to execute operating system commands. It stems from improper sanitization of input passed to a shell execution context, as detailed by SecurityWeek.
  • Root Cause: While the tool uses a check_safe() function to filter dangerous commands, it relies on a regex-based blacklist. This approach is fundamentally flawed as it can be bypassed using alternative shell syntax, encoding, or command obfuscation, according to CERT Coordination Center (CERT/CC).
  • Exploitation: An attacker can exploit this through prompt injection. By providing crafted content (such as a malicious document, log line, or chat prompt) that the agent is designed to process, the attacker can trick the agent into executing arbitrary OS commands with the privileges of the agent process.
  • Impact: Successful exploitation allows for Remote Code Execution (RCE), enabling attackers to modify files, exfiltrate API keys and sensitive data, or move laterally within a network.
  • Status: As of early March 2026, no official patch or statement has been provided by the vendor. Security researchers at Medium recommend sandboxing agents with shell capabilities and using strict allowlists instead of blacklists.

#code  #critical  #cve-2026-2256:  #enables  #execution  #ms-agent  #news  #remote  #shell  #tool  #vulnerability   —   News