CVE-2026-51922
Description
AI Translation Available
agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
https://gist.github.com/Ro1ME/78910899a99e2ba702d588e477d0755f
https://github.com/agentscope-ai/agentscope/issues/1645