Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51856

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 AgentScope 1.0.18、1.0.19 和 1.0.20 版本中,当 RealtimeAgent 会话将 暴露为可用工具时,远程 WebSocket 用户可以诱导该 Agent 调用此工具,从而在服务端环境中执行任意 Python 代码。在已验证的攻击路径中, 方法会将模型生成的工具调用转发至 ,而后者在调用 时,并未在该路径上施加额外的审批机制或隔离边界。

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51856

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51856

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51856

请登录查看更多情报信息。

Other References for CVE-2026-51856 (2)

Same Patch Batch · n/a · 2026-09-30 · 20 CVEs total

CVE-2026-51568 8.1 HIGH CVE-2026-51568
CVE-2026-51570 8.1 HIGH CVE-2026-51570
CVE-2026-103227 6.3 MEDIUM GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow
CVE-2026-103118 4.3 MEDIUM GraphicsMagick WPG File wpg.c ExtractPostscript recursion
CVE-2026-51864 CVE-2026-51864
CVE-2026-51866 CVE-2026-51866
CVE-2026-51869 CVE-2026-51869
CVE-2026-51862 CVE-2026-51862
CVE-2026-51852 CVE-2026-51852
CVE-2026-51859 CVE-2026-51859
CVE-2026-51853 CVE-2026-51853
CVE-2026-51857 CVE-2026-51857
CVE-2026-51871 CVE-2026-51871
CVE-2026-51860 CVE-2026-51860
CVE-2026-51872 CVE-2026-51872
CVE-2026-51867 CVE-2026-51867
CVE-2026-51861 CVE-2026-51861
CVE-2026-51858 CVE-2026-51858
CVE-2026-51870 CVE-2026-51870

IV. Related Vulnerabilities

V. Comments for CVE-2026-51856

No comments yet


Leave a comment