CVE-2026-6606Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-20); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Technical Details · 2026-04-20: 104-2004-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-211
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-6606 A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_age… https://www.cve.org/CVERecord?id=CVE-2026-6606

    Post summary

    The text announces CVE-2026-6606 in modelscope agentscope up to 1.0.18, noting the affected function, but provides no evidence of a PoC, exploit, active use, patch, or technical specifics beyond the identifier.

    0000096
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6606 Server-Side Request Forgery in ModelScope AgentScope Up to 1.0.18 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6606

    Post summary

    CVE-2026-6606 is a newly disclosed SSRF vulnerability affecting ModelScope AgentScope up to version 1.0.18, with no evidence of exploitation, PoC, or patch information in the provided text.

    0000038
    4.0K followersView on X

Explore more