mediumCVSS 7.3Vulnerability

CVE-2026-6606

A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
AgentScope vulnerable to Server-Side Request Forgery
epss_score
0.00284
cvss_score
7.3
ghsa_published
2026-04-20T06:31:28Z
source_url
https://github.com/advisories/GHSA-crx8-wpv6-jrj2
ghsa_updated
2026-04-28T23:20:52Z
ghsa_id
GHSA-crx8-wpv6-jrj2
cve_id
CVE-2026-6606
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.20584

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/agentscope

AFFECTS (1)

[Software]pip/agentscope

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

Explore deeper with Ninja Signal's threat intelligence graph