Fetching from the wire…
Public story · 2026-03-11 · source-backed
A command injection vulnerability in ModelScope's MS-Agent lets attackers hijack agent workflows via crafted inputs in prompts, documents, or logs — the check_safe() regex denylist is bypassable. This is a new failure class: indirect prompt-to-tool-to-shell compromise. Unpatched. PoC available on GitHub. SecQube
Each link below shares sources, entities, or timing with this story.
Shared entities / Shared topic / What happened next
Both cover Agent, CVE, ModelScope; overlapping topics (agent, attacker, command); picks up the Agent thread on 2026-06-23.
Shared entities / Shared topic / Earlier coverage
Both cover Agent, GitHub, PoC; overlapping topics (agent, document); earlier Agent coverage from 2026-02-22.
Shared entities / Shared topic / What happened next / Tension
Both cover Agent, GitHub; overlapping topics (agent, command); picks up the Agent thread on 2026-05-17.
Both cover CVE, GitHub; overlapping topics (agent, command); picks up the CVE thread on 2026-03-20.
Shared entities / What happened next
Both cover CVE, GitHub, PoC; picks up the CVE thread on 2026-08-04.
Shared entities / Earlier coverage
Both cover Agent, CVE, GitHub; earlier Agent coverage from 2026-02-23.
Shared entities / Shared topic / What happened next
Both cover Agent, GitHub; overlapping topics (agent, injection); picks up the Agent thread on 2026-08-06.
Both cover CVE, PoC; overlapping topics (agent, attacker); picks up the CVE thread on 2026-07-11.