Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2256

Опубликовано: 02 мар. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

A flaw was found in ModelScope, Red Hat AI Inference Server, and Red Hat OpenShift AI. This command injection vulnerability allows a remote attacker to execute arbitrary operating system commands. The exploitation occurs through crafted prompt-derived input, leading to arbitrary code execution on the affected system.

Отчет

This MODERATE impact command injection vulnerability affects Red Hat AI Inference Server and Red Hat OpenShift AI (RHOAI) through the ModelScope ms-agent component. An attacker can execute arbitrary operating system commands by providing specially crafted input derived from prompts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis-preview/vllm-cuda-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-router-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-storage-initializer-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2444016ModelScope: ModelScope, Red Hat AI Inference Server, Red Hat OpenShift AI: Arbitrary code execution via crafted prompt input

EPSS

Процентиль: 85%
0.02312
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
28 дней назад

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

CVSS3: 6.5
github
28 дней назад

MS-Agent vulnerable to Command Injection

EPSS

Процентиль: 85%
0.02312
Низкий

6.5 Medium

CVSS3