Critical MS-Agent Vulnerability Lets Attackers Hijack AI Agents for Full System Control
CVE-2026-2256 in ModelScope's MS-Agent framework enables command injection through prompt manipulation, with no vendor patch available.
Tag
CVE-2026-2256 in ModelScope's MS-Agent framework enables command injection through prompt manipulation, with no vendor patch available.
Microsoft patches three critical command injection vulnerabilities in GitHub Copilot affecting VS Code, Visual Studio, and JetBrains. Over 20 million developers at risk from unsanitized shell inputs.