CVE-2026-51922
Received Received - Intake

Code Injection in AgentScope Tool

Vulnerability report for CVE-2026-51922, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
agentscope agentscope 1.0.20

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-51922 is a code injection vulnerability in AgentScope version 1.0.20. It exists in the execute_shell_command function in src/agentscope/tool/_coding/_shell.py. Attacker-controlled input is executed as code or commands without proper validation, allowing arbitrary command execution if the function is triggered through an exposed entry point.

Detection Guidance

Check if AgentScope v1.0.20 is installed by searching for the execute_shell_command function in src/agentscope/tool/_coding/_shell.py. Look for direct calls to asyncio.create_subprocess_shell without input validation or safeguards.

Commands to detect: grep -r 'execute_shell_command' /path/to/agentscope/ && grep -r 'create_subprocess_shell' /path/to/agentscope/

Impact Analysis

This vulnerability allows attackers to execute arbitrary shell commands on the system running AgentScope v1.0.20. Potential impacts include creating or deleting files, stealing sensitive data, installing malware, or taking control of the affected system. Attackers could exploit it by sending malicious prompts through the agent's interface if the tool is registered in a Toolkit.

Compliance Impact

This vulnerability could lead to unauthorized data access, modification, or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using AgentScope v1.0.20 may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade AgentScope to a patched version if available. Disable the ReActAgent tool or remove execute_shell_command from exposed entry points. Implement input validation, user confirmation, and sandboxing for shell commands.

Avoid using create_subprocess_shell for model-controlled inputs. Restrict tool access and monitor for unusual command execution patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51922. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart