Server-Side Request Forgery Vulnerability in ModelScope AgentScope by ModelScope
CVE-2026-6605
Key Information:
- Vendor
Modelscope
- Status
- Vendor
- CVE Published:
- 20 April 2026
Badges
What is CVE-2026-6605?
A security flaw exists in ModelScope AgentScope versions up to 1.0.18, specifically within the _get_bytes_from_web_url function located in the _common.py file. This vulnerability allows for server-side request forgery (SSRF), enabling attackers to initiate remote exploits. The issue was reported to the vendor, however, there has been no response to address this critical security concern. Exploit details have been made public, raising the risk of potential attacks on affected systems.
Affected Version(s)
agentscope 1.0.0
agentscope 1.0.1
agentscope 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
