Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51922

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

agentscope v1.0.20 存在代码注入漏洞(位于 src/agentscope/tool/_coding/_shell.py 中的 execute_shell_command 函数)。根据暴露的入口点不同,攻击者可以触发由攻击者控制的代码或命令执行。

AI Predicted 9.8 Difficulty: Trivial

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51922

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51922

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51922

请登录查看更多情报信息。

Proof of Concept for CVE-2026-51922 (1)

Other References for CVE-2026-51922 (1)

Same Patch Batch · n/a · 2026-10-02 · 14 CVEs total

CVE-2026-51906 TaskingAI v0.3.0 DALL-E 3目录遍历漏洞
CVE-2026-51904 SuperAGI≤v0.0.14越权漏洞
CVE-2026-51907 TaskingAI v0.3.0插件目录遍历漏洞
CVE-2026-51901 SuperAGI <=0.0.14 越权访问漏洞
CVE-2026-51898 pandas-ai 3.0.0 代码执行器存在代码注入漏洞
CVE-2026-51899 SuperAGI <0.0.14 存在水平权限漏洞
CVE-2026-51916 TransformerOptimus SuperAGI v0.0.14 越权删除漏洞
CVE-2026-51918 FinRobot 1.0.0 CodingUtils.create_file_with_code() 代码注入漏洞
CVE-2026-51911 Vanna v2.0.2代码注入漏洞
CVE-2026-51917 FinRobot v1.0.0 CodingUtils模块代码注入漏洞
CVE-2026-51915 TransformerOptimus SuperAGI v0.0.14工具控制器越权漏洞
CVE-2026-51914 TransformerOptimus SuperAGI v0.0.14 存在错误访问控制漏洞
CVE-2026-67989 Ruby_llm Ruby 3.1.x ReDoS漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-51922

No comments yet


Leave a comment