CVE-2026-6605
Last modified
CVE-2026-6605 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6605?
How severe is CVE-2026-6605?
How do I fix CVE-2026-6605?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66037FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an u…5.5
- CVE-2026-66038FFmpeg through 8.1.2, fixed in commit 8670835, contains an i…6.5
- CVE-2026-66039FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a si…7.8
- CVE-2026-6604A vulnerability was identified in modelscope agentscope up t…7.3
- CVE-2026-66040FFmpeg through 8.1.2, fixed in commit b506faf, contains a he…8.8
- CVE-2026-66041FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains …7.8
- CVE-2026-66050NitroShare Desktop through 0.3.4 contains a path traversal v…8.7
- CVE-2026-66051Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-66053Improper Validation of Certificate with Host Mismatch vulner…5.9
- CVE-2026-66058Frappe is a full-stack web application framework. Prior to 1…5.3
- CVE-2026-66059Frappe is a full-stack web application framework. Prior to 1…5.3
- CVE-2026-6606A weakness has been identified in modelscope agentscope up t…7.3
Are you affected by CVE-2026-6605?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
