CVE-2026-2256Disclosure

CRITICALCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 35 mentions across 16 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 30 signals
  • Disclosure: 24 classified signals
  • General: 3 classified signals
  • Peaked 13d ago at 8 mentions (2026-03-03); latest day: 1
  • 35 total mentions across 16 days

Deep dive

Activity timeline35 mentions / 16d
02468Mentions · 2026-02-25: 1Mentions · 2026-03-02: 2Mentions · 2026-03-03: 8Mentions · 2026-03-04: 4Mentions · 2026-03-05: 4Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-14: 1Mentions · 2026-03-25: 2Mentions · 2026-03-26: 2Mentions · 2026-03-27: 4Mentions · 2026-03-30: 1Mentions · 2026-06-04: 1PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-30: 1Exploit Tool / Code · 2026-03-05: 1Exploit Tool / Code · 2026-03-25: 1Exploit Tool / Code · 2026-03-30: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-30: 1Patch / Workaround · 2026-03-03: 2Patch / Workaround · 2026-03-04: 3Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 6Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 4Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 4Technical Details · 2026-03-30: 1Technical Details · 2026-06-04: 102-2503-0203-0303-0403-0503-0603-0703-0803-0903-1003-1403-2503-2603-2703-3006-04
Signal classification5 categories
Disclosure
2468.6%
Active Exploitation
514.3%
General
38.6%
Patch
25.7%
PoC
12.9%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-251
General1
2026-03-022
Disclosure2
2026-03-038
Disclosure7General1
2026-03-044
Disclosure4
2026-03-054
Disclosure2Patch1PoC1
2026-03-061
Active Exploitation1
2026-03-071
Active Exploitation1
2026-03-081
Disclosure1
2026-03-091
Active Exploitation1
2026-03-101
Patch1
2026-03-141
General1
2026-03-252
Disclosure2
2026-03-262
Active Exploitation1Disclosure1
2026-03-274
Disclosure4
2026-03-301
Active Exploitation1
2026-06-041
Disclosure1
Full discourse20 posts
  • kokumօtօ@__kokumoto
    Disclosure

    AIエージェントのMS-Agentに未修正の脆弱性。CVE-2026-2256はプロンプトインジェクション。コンピュータ上でコマンドを直接実行できる「シェル」ツールにおける悪用対策が禁止リストのため、迂回して任意のコマンドを実行可能。 https://securityonline.info/cve-2026-2256-unpatched-flaw-in-ms-agent-lets-hackers-hijack-ai-assistants/

    Post summary

    The post announces an unpatched prompt injection vulnerability (CVE‑2026‑2256) in MS‑Agent that permits arbitrary command execution by bypassing a banned list, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    010651.1K
    7.3K followersView on X
  • ZeitTrender@ZeitTrender
    Disclosure

    ⚠️ Critical flaw in ModelScope MS-Agent lets attackers hijack AI agents and take full system control through unsanitized shell commands. CVE-2026-2256 — no patch available yet. AI agent security is getting ugly fast. #AISecurity #AIagents https://cyberpress.org/critical-ms-agent-vulnerability-allows-attackers-to-hijack-ai-agents-and-gain-full-system-control/

    Post summary

    CVE-2026-2256 is a critical flaw in ModelScope MS‑Agent that allows attackers to hijack AI agents and gain full system control via unsanitized shell commands. A patch is not yet available.

    30000104
    46 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 تحذير من Cisco: استغلال لثغرات حرجة في SD-WAN Manager أصدرت Cisco تحذيرًا أمنيًا عاجلاً بشأن استغلال لثغرتين حرجتين ضمن منتجها Catalyst SD-WAN Manager (بما في ذلك CVE-2026-2256 و CVE-2026-20128). تتيح هذه الثغرات للمهاجمين تنفيذ عمليات استغلال نشطة في البيئات التشغيلية، ما يشكل تهديدًا مباشرًا للأنظمة المتأثرة وقد يؤدي إلى اختراقها. تحث Cisco المستخدمين بشدة على اتخاذ إجراءات فورية للتخفيف من المخاطر. 🔗 للمزيد: https://securityonline.info/under-attack-cisco-urges-immediate-action-as-hackers-actively-exploit-sd-wan-manager-flaws/

    Post summary

    Cisco’s urgent advisory reveals that CVE-2026-2256 and CVE-2026-20128 in Catalyst SD‑WAN Manager are being actively exploited, prompting immediate mitigation actions.

    0003084
    60 followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة حرجة في Nginx UI تُسرب مفاتيح فك التشفير وأسرار الخادم اكتشف باحثون ثغرات حرجة في واجهة Nginx UI، وهي أداة شائعة لإدارة مجموعات خوادم Nginx. تُمكن هذه الثغرات غير الموثقة، والمُتتبعة ضمن CVE-2026-27944 و CVE-2026-2256، من تسريب مفاتيح فك التشفير وأسرار الخادم الحساسة. يُشكل هذا الاختراق تهديداً بالغاً لأمن البيانات وسرية الأنظمة المُستهدفة، ما يتطلب إجراءات فورية. 🔗 للمزيد: https://securityonline.info/unauthenticated-nginx-ui-flaw-leaks-decryption-keys-and-server-secrets/

    Post summary

    Researchers have identified critical, unauthenticated flaws in the Nginx UI (CVE‑2026‑27944 and CVE‑2026‑2256) that can leak decryption keys and server secrets.

    0002068
    62 followersView on X
  • Permission Protocol@PermissionPrtcl
    Active Exploitation

    A vendor invoice just gave a Microsoft agent terminal access to its host system. The agent read the file, hit the Shell tool, ran the commands hidden in the formatting. CVE-2026-2256. No patch coming.

    Post summary

    The text reports active exploitation of CVE‑2026‑2256 via a file-format trick that granted Microsoft agent terminal access, notes that no patch will be released, but offers no PoC or technical details.

    1001036
    9 followersView on X
  • Oktsec@oktsec
    PoC

    CVE-2026-2256. CVSS 9.8. From a user prompt to full system compromise. ModelScope's ms-agent has a Shell tool. The defense? A denylist called check_safe(). Bypassed with basic command obfuscation. No authentication required. A crafted prompt reads secrets, drops payloads, establishes persistence, pivots laterally. PoC is public. If you're running ms-agent ≤ 1.6.0rc1, update now. The pattern keeps repeating: give an agent a shell, add a denylist, ship it, get a CVSS 9.8. The fix isn't a better denylist. It's not giving agents unrestricted shell access in the first place.

    Post summary

    CVE-2026-2256 exposes ms‑agent to full system compromise with a publicly available PoC; the vulnerability is severe (CVSS 9.8) and requires an immediate patch to version 1.6.0rc1 or newer.

    1001072
    197 followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-2256: MS-Agentの未修正の脆弱性により、ハッカーがAIアシスタントを乗っ取ることができる CVE-2026-2256: Unpatched Flaw in MS-Agent Lets Hackers Hijack AI Assistants #DailyCyberSecurity (Mar 3) https://securityonline.info/cve-2026-2256-unpatched-flaw-in-ms-agent-lets-hackers-hijack-ai-assistants/

    Post summary

    A new unpatched vulnerability in MS‑Agent (CVE‑2026‑2256) could allow hackers to hijack AI assistants, but no PoC, exploit, or patch details are provided.

    00020238
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    An unpatched zero-day flaw (CVE-2026-2256) in the MS-Agent framework allows hackers to use prompt injection to execute OS commands and hijack AI systems. #MSAgent #AISecurity #CyberSecurity #PromptInjection #CVE #InfoSec #ZeroDay https://securityonline.info/cve-2026-2256-unpatched-flaw-in-ms-agent-lets-hackers-hijack-ai-assistants/

    Post summary

    An unpatched zero‑day vulnerability (CVE‑2026‑2256) in the MS‑Agent framework enables prompt injection that can lead to OS command execution and AI system hijacking.

    00020274
    10.5K followersView on X
  • Erik Newton@newtonlaw
    Active Exploitation

    How bad is it right now? 200,000+ OpenClaw instances exposed to the internet. Plaintext memory. Atomic Stealer hit 2,200+ malicious skills targeting agent users. A zero-day in MS-Agent (CVE-2026-2256) lets prompt injection escalate to full shell execution — PoC is public, no patch. Agent breaches up 340% YoY.

    Post summary

    A zero‑day in MS‑Agent (CVE‑2026‑2256) has a publicly available PoC and is being actively exploited—over 200,000 OpenClaw instances are exposed, and no patch is yet available.

    10000148
    5.9K followersView on X
  • The Agent Economist@The_Agent_Econ
    Disclosure

    CVE-2026-2256 — the ModelScope MS-Agent framework has a command injection flaw. researchers bypassed its blacklist filters. crafted prompts execute OS commands with full agent privileges. PoC is public. no patch yet. if you're running MS-Agent: sandbox it or shut it down. now.

    Post summary

    Researchers disclosed a command injection flaw in ModelScope MS‑Agent (CVE‑2026‑2256), released a public PoC, and warned users to sandbox or shut down the service pending a patch.

    0001094
    12 followersView on X
  • Ali Noori | Tusiro@omniuxai
    General

    This isn't theory. Look at CVE-2025-53773. A prompt injection can trigger "YOLO Mode" in your assistant, allowing Remote Code Execution (RCE) directly on your machine. And CVE-2026-2256 just proved that even MS-Agent isn't safe from logic-bypass attacks. https://t.co/nkwi3gmUN3

    Post summary

    The tweet highlights RCE and logic‑bypass issues in two CVEs but does not provide a PoC, exploit code, active exploitation evidence, or patch details.

    10000178
    2 followersView on X
  • iototsecnews@iototsecnews
    Patch

    ModelScope MS-Agent の脆弱性 CVE-2026-2256:リモート・ハイジャックと乗っ取りの恐れ https://iototsecnews.jp/2026/03/03/ms-agent-vulnerability-exposes-ai-agents-to-remote-hijacking-granting-full-system-control/ AI エージェント構築フレームワーク ModelScope MS-Agent において、基盤となるシステムを完全に支配される恐れのある深刻な脆弱性 CVE-2026-2256 が発見されました。この問題の原因は、AI エージェントが OS コマンドを実行するための “Shell ツール” において、入力された命令の内容が十分に検証されていないことにあります。このフレームワークには、実行前に危険なコマンドをブロックする check_safe() という検査機能が備わっています。 しかし、この機能は拒否リストに含まれる特定の言葉をフィルタリングするだけの不完全なものでした。そのため、攻撃者が文書の要約や解析をエージェントに依頼する際に、その指示の中に巧妙に細工した悪意のコマンドを紛れ込ませるプロンプト・インジェクションを行うことで、簡単に検査をすり抜けることが可能になっていました。脆弱性 CVE-2026-2256 に対するパッチが提供され、このフレームワークに依存する AI エージェントがアップデートされ、プロンプト・インジェクションが減ることを期待します。 #CVE20262256 #ModelScope #MSAgent #PromptInjection #Vulnerability

    Post summary

    A newly disclosed vulnerability CVE-2026-2256 in ModelScope MS-Agent allows prompt injection that can lead to remote hijacking; a patch has already been issued to mitigate the issue.

    01000151
    484 followersView on X
  • WhiteTrashTrades@Double00Kevin
    Active Exploitation

    What dropped today (while these clowns are still selling unsecured garbage bots that get your account nuked): • ModelScope MS-Agent/CVE-2026-2256 lets attackers inject crafted prompts for arbitrary OS command execution leading to full system compromise including data theft, persistence, and pivoting.8e34b1 March 8, 2026 + crushes small-biz ops by nuking your AI agents and exposing client data + these "open-source" frameworks are just exploit delivery systems in disguise. http://securityweek.com These tools keep shipping desktop-level privileges with zero isolation. That’s not innovation — that’s an open root shell wearing a hoodie. And the idiots selling "easy AI bots" on X? They’re the ones getting you banned while I’m over here with actual frameworks. My non-negotiable framework for every client deployment: LXC/VM isolation only (Ubuntu 24.04, no host mounts ever) Strict egress allowlist + syscall monitoring Zero secrets in agent memory Human gate on every high-risk action If you’re a small biz running (or about to run) agentic AI in 2026 and don’t want to be next week’s headline or banned for using some clown’s bot, DM me. I build the versions that don’t fold — and call out the rest. #AISecurity #CyberSecurity #CISSP #AgenticAI #CallOutTheClowns Verified sources at the bottom for your viewing pleasure

    Post summary

    The message highlights that CVE‑2026‑2256 in ModelScope MS‑Agent is being actively exploited to execute arbitrary OS commands via crafted prompts, prompting a call for secure deployment practices.

    0000154
    4.4K followersView on X
  • ModelScope@ModelScope2022
    Patch

    @SecurityWeek CVE-2026-2256 has been patched in ms-agent. The Shell tool's regex denylist bypass that allowed command injection via http://subprocess.run(..., shell=True) is now mitigated by moving execution into an isolated Docker sandbox. Details 👇 https://github.com/modelscope/ms-agent/pull/880

    Post summary

    CVE-2026-2256 was patched in ms-agent, with the command injection bypass mitigated by a Docker sandbox; the post confirms the fix but shows no evidence of exploitation or a PoC.

    00010197
    6.5K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 MS-Agent RCE Flaw (CVE-2026-2256) Lets Prompt Injection Hijack AI Agents for Full System Control A critical command-injection bug in ModelScope’s MS-Agent “Shell tool” (CVSS 9.8) allows attackers to bypass the weak denylist `check_safe()` filter via obfuscation and execute arbitrary OS commands through prompt injection, granting control with the agent’s privileges. No vendor patch was available at CERT/CC disclosure, so isolation/sandboxing, least-privilege, and strict allowlists are the recommended mitigations. 🎯 Target: Global/AI Agent Frameworks & Autonomous Tooling #️⃣ Category: #Vulnerability #AI_Threats #BlueTeam 🔗 URL: https://cybersecuritynews.com/ms-agent-vulnerability/

    Post summary

    The post announces a critical command‑injection flaw (CVE‑2026‑2256) in ModelScope’s MS‑Agent shell tool with CVSS 9.8, detailing how the denylist is bypassed and OS commands can be executed; no patch yet, but isolation and privilege restrictions are recommended.

    1000063
    262 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-2256: Unpatched Flaw in MS-Agent Lets Hackers Hijack AI Assistants https://securityonline.info/cve-2026-2256-unpatched-flaw-in-ms-agent-lets-hackers-hijack-ai-assistants/

    Post summary

    The article announces a new unpatched vulnerability in MS‑Agent that could allow attackers to hijack AI assistants, but it provides no PoC, exploit code, or evidence of active exploitation.

    0001046
    70 followersView on X
  • Agenticai Flow - エージェンティックAIメディア@agenticai_flow
    Disclosure

    #AgenticAI #自動化 CVE-2026-2256:MS AgentにRCE脆弱性。プロンプトインジェクションでコード実行可能。CVSS 9.8。AIエージェントの普及に伴い、インジェクション対策が急務です。 http://stateofsurveillance.org/news/ms-agent-cve-2026-2256-ai-agent-security-enterprise-2026/

    Post summary

    The post announces CVE‑2026‑2256, an RCE flaw in MS Agent triggered by prompt injection with a CVSS of 9.8, underscoring the urgent need for injection mitigations in AI agents.

    0000041
    49 followersView on X
  • NY-squared AI@NYsquaredAI
    Disclosure

    CVE-2026-2256. Critical vulnerability in MS-Agent framework. Prompt Injection can hijack AI agents. Full system control achieved. If you don't guard the input, you can't protect the output. #PromptInjection #AISecurity #CVE

    Post summary

    The statement announces a critical Prompt‑Injection flaw in the MS‑Agent framework capable of yielding full system control if input is not protected.

    000001
    26 followersView on X
  • NY-squared AI@NYsquaredAI
    Disclosure

    CVE-2026-2256。 MS-Agentフレームワークに Critical脆弱性。 Prompt Injectionで AIエージェントをハイジャック。 システム完全制御が可能。 エージェントの入口を守らなければ 出口も守れない。 #PromptInjection #CVE

    Post summary

    The text announces CVE‑2026‑2256 as a critical prompt‑injection flaw in the MS‑Agent framework, noting it can hijack the agent and seize system control, but offers limited technical detail and no evidence of exploitation or mitigation.

    000000
    26 followersView on X
  • NY-squared AI@NYsquaredAI
    Disclosure

    CVE-2026-2256. CVSS 9.8. Prompt Injection hijacks AI agents. Full system control achieved. Guard the input, or lose the output. Multi-layer defense is urgent. #PromptInjection #AISecurity

    Post summary

    The text announces CVE‑2026‑2256, a CVSS 9.8 prompt‑injection vulnerability that can hijack AI agents and grant full system control, urging multi‑layer defense.

    000000
    26 followersView on X

Explore more