Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2256

Опубликовано: 02 мар. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

A flaw was found in ModelScope, Red Hat AI Inference Server, and Red Hat OpenShift AI. This command injection vulnerability allows a remote attacker to execute arbitrary operating system commands. The exploitation occurs through crafted prompt-derived input, leading to arbitrary code execution on the affected system.

Отчет

This MODERATE impact command injection vulnerability affects Red Hat AI Inference Server and Red Hat OpenShift AI (RHOAI) through the ModelScope ms-agent component. An attacker can execute arbitrary operating system commands by providing specially crafted input derived from prompts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis-preview/vllm-cuda-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-router-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-storage-initializer-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2444016ModelScope: ModelScope, Red Hat AI Inference Server, Red Hat OpenShift AI: Arbitrary code execution via crafted prompt input

EPSS

Процентиль: 74%
0.01611
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
6 месяцев назад

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

CVSS3: 6.5
github
6 месяцев назад

MS-Agent vulnerable to Command Injection

EPSS

Процентиль: 74%
0.01611
Низкий

6.5 Medium

CVSS3