mediumCVSS 7.3Vulnerability

CVE-2026-6604

A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py of the component Cloud Metadata Endpoint. Such manipulation of the argument image_url/audio_file_url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
AgentScope vulnerable to Server-Side Request Forgery
epss_score
0.00284
cvss_score
7.3
ghsa_published
2026-04-20T06:31:27Z
source_url
https://github.com/advisories/GHSA-659x-hm75-hpv7
ghsa_updated
2026-04-28T23:19:31Z
ghsa_id
GHSA-659x-hm75-hpv7
cve_id
CVE-2026-6604
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.20584

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/agentscope

AFFECTS (1)

[Software]pip/agentscope

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

Explore deeper with Ninja Signal's threat intelligence graph