Impact
The vulnerability is a code injection flaw in agentscope's execute_shell_command function within the _shell.py module. By controlling the input to this function, an attacker can inject arbitrary system commands executed with the privileges of the agentscope process, resulting in full remote code execution. The underlying weakness aligns with command injection (CWE-78) and code injection (CWE-94).
Affected Systems
agentscope version 1.0.20 is affected. No other versions are currently documented as vulnerable, but any installation of this exact release should be considered at risk.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the nature of the flaw grants an attacker complete control over the host system if they can exercise the execute_shell_command entry. The lack of an explicit exploitation path in the public data suggests the attack vector depends on the exposure of the vulnerable entry, likely via an unvalidated input endpoint. Given the severity of remote code execution, the risk remains high and should be treated as such.
OpenCVE Enrichment