---
id: CVE-2026-51856
title: >-
  In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session
  exposes execute_python_code as an available tool, a remote WebSocket user can
  prompt the agent to call that tool and run Python code in the service
  environment
summary: >-
  In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session
  exposes execute_python_code as an available tool, a remote WebSocket user can
  prompt the agent to call that tool and run Python code in the service
  environment. In t…
severity: none
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:11.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51856'
references:
  - url: 'https://gist.github.com/Ro1ME/c383f66d1fd6de40b6693f9b6cc181e7'
    label: cve@mitre.org
  - url: 'https://github.com/agentscope-ai/agentscope/issues/1563'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.842Z'
---

## Overview

In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
