mediumCVSS 7.3Vulnerability

CVE-2026-6605

A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
AgentScope vulnerable to Server-Side Request Forgery
epss_score
0.00326
cvss_score
7.3
ghsa_published
2026-04-20T06:31:27Z
source_url
https://github.com/advisories/GHSA-8ggf-r3vm-p3jc
ghsa_updated
2026-04-28T23:20:11Z
ghsa_id
GHSA-8ggf-r3vm-p3jc
cve_id
CVE-2026-6605
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.25271

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/agentscope

AFFECTS (1)

[Software]pip/agentscope

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

Explore deeper with Ninja Signal's threat intelligence graph