gist.github.comexploit
https://gist.github.com/YLChen-007/ced2d438ae79a5a11cea663c1ba2c954 CVE-2026-6605
MEDIUM
modelscope agentscope Internal Service _common.py _get_bytes_from_web_url server-side request forgery
Record summary
CVE-2026-6605 has a selected CVSS score of 6.9 (medium).
Description
A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 20, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
agentscopeBrowse modelscope / agentscope | CVE List | 1.0.0 | affected |
| 1.0.1 | affected | ||
| 1.0.2 | affected | ||
| 1.0.3 | affected | ||
| 1.0.4 | affected | ||
| 1.0.5 | affected | ||
| 1.0.6 | affected | ||
| 1.0.7 | affected | ||
| 1.0.8 | affected | ||
| 1.0.9 | affected | ||
| 1.0.10 | affected | ||
| 1.0.11 | affected | ||
| Showing 12 of 19 version ranges | |||
agentscopeBrowse PyPI / agentscope | GitHub Advisory | Through 1.0.18 | affected |
References
6github.com
https://github.com/agentscope-ai/agentscope nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-6605 Submit #792225 | AgentScope <= 1.0.18 Server-Side Request Forgery (CWE-918)Third-party advisory
https://vuldb.com/submit/792225 VDB-358240 | modelscope agentscope Internal Service _common.py _get_bytes_from_web_url server-side request forgeryvdb entryTechnical description
https://vuldb.com/vuln/358240 VDB-358240 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/vuln/358240/cti