{"id":"CVE-2026-51856","title":"In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment","summary":"In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In t…","severity":"none","published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:17:11.520","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51856","references":[{"url":"https://gist.github.com/Ro1ME/c383f66d1fd6de40b6693f9b6cc181e7","label":"cve@mitre.org"},{"url":"https://github.com/agentscope-ai/agentscope/issues/1563","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T21:25:07.842Z","slug":"CVE-2026-51856","body":"## Overview\n\nIn agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}