Vulnerability  ·  2026-10-01

Agent framework code-execution batch: agentscope RealtimeAgent RCE, camel-ai no-approval code/shell execution

VulnerabilityHigh impactGlobalCVE-2026-51856
A coordinated 2026-09-26 disclosure batch (researcher Ro1ME, MITRE-assigned) covering agent frameworks that let model output reach code/shell execution with no human-approval or sandbox boundary. Documented reproduction notes provided; reported to vendors via GitHub issues before publication.
These are the canonical 'excessive agency' failures: if any prompt-injected or malicious tool output steers the model to the code/shell tool, there is no approval gate, so an indirect prompt injection becomes arbitrary code execution inside the agent service — the reference pattern for agentic RCE in widely-used open frameworks.
agentscope: a remote WebSocket user prompts the RealtimeAgent to invoke the exposed execute_python_code tool, which runs model-produced Python in the service process with no approval/isolation boundary (CVE-2026-51856). camel-ai: CodeExecutionToolkit runs model-produced Python via SubprocessInterpreter (CVE-2026-51857) and TerminalToolkit.shell_exec allows prompt-driven shell commands (CVE-2026-51858), both without an approval boundary.
agentscope 1.0.18–1.0.19 (RealtimeAgent.execute_python_code); camel-ai 0.2.91a1–a3 (CodeExecutionToolkit, TerminalToolkit.shell_exec)
Update agentscope beyond 1.0.19 and camel-ai beyond 0.2.91a3; until then disable execute_python_code/CodeExecutionToolkit, restrict WebSocket clients, and add approval boundaries.
NVD CVE-2026-51856Ro1ME disclosure (GitHub gists)thehackerwire agentscope analysis
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →