What happened
A coordinated 2026-09-26 disclosure batch (researcher Ro1ME, MITRE-assigned) covering agent frameworks that let model output reach code/shell execution with no human-approval or sandbox boundary. Documented reproduction notes provided; reported to vendors via GitHub issues before publication.
Why it matters
These are the canonical 'excessive agency' failures: if any prompt-injected or malicious tool output steers the model to the code/shell tool, there is no approval gate, so an indirect prompt injection becomes arbitrary code execution inside the agent service — the reference pattern for agentic RCE in widely-used open frameworks.
Attack vector
agentscope: a remote WebSocket user prompts the RealtimeAgent to invoke the exposed execute_python_code tool, which runs model-produced Python in the service process with no approval/isolation boundary (CVE-2026-51856). camel-ai: CodeExecutionToolkit runs model-produced Python via SubprocessInterpreter (CVE-2026-51857) and TerminalToolkit.shell_exec allows prompt-driven shell commands (CVE-2026-51858), both without an approval boundary.
Affected systems
agentscope 1.0.18–1.0.19 (RealtimeAgent.execute_python_code); camel-ai 0.2.91a1–a3 (CodeExecutionToolkit, TerminalToolkit.shell_exec)
Mitigation
Update agentscope beyond 1.0.19 and camel-ai beyond 0.2.91a3; until then disable execute_python_code/CodeExecutionToolkit, restrict WebSocket clients, and add approval boundaries.