CVE-2026-51856
Received Received - Intake

Remote Code Execution in agentscope RealtimeAgent

Vulnerability report for CVE-2026-51856, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In agentscope versions 1.0.18, 1.0.19, and 1.0.19, a vulnerability exists where a remote WebSocket user can exploit the RealtimeAgent session to run arbitrary Python code. This occurs because the execute_python_code tool is exposed as an available function, and the RealtimeAgent._acting method forwards tool calls to Toolkit.call_tool_function without proper approval or isolation, allowing code execution in the service environment.

Detection Guidance

To detect this vulnerability, check if agentscope 1.0.18, 1.0.19, or 1.0.19 is running and if RealtimeAgent exposes execute_python_code as a tool. Inspect network traffic for WebSocket connections to the agent service. Look for unexpected Python code execution attempts or unauthorized tool calls.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary Python code on the affected system remotely. This could lead to unauthorized access, data theft, system compromise, or disruption of service. If the service runs with elevated privileges, the impact could be severe, including full system takeover or lateral movement within a network.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other regulations due to unauthorized code execution and potential data breaches. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A breach could result in legal penalties, fines, and reputational damage.

Mitigation Strategies

Immediately upgrade agentscope to a patched version where execute_python_code is not exposed as a tool or requires additional approval. Disable the RealtimeAgent session's ability to call execute_python_code remotely. Review and restrict WebSocket user permissions to prevent unauthorized tool invocation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51856. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart