CVE-2026-6605 | modelscope agentscope up to 1.0.18 Internal Service _common.py _get_bytes_from_web_url server-side request forgery
A vulnerability was found in modelscope agentscope up to 1.0.18. It has been rated as critical. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-6605. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More