Feed/CVE-2026-6606
CVE-2026-6606HIGHCVSS 7.3

CVE-2026-6606

Published Apr 19, 2026·Updated Jun 17, 2026

NVD Description

A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Public Exploits & PoCs6 found

[POC] CVE-2026-66066 — CVE-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged variation. CVSS 9.5 | Rails < 8.1.3.1

[POC] CVE-2026-66066 — kindarails2shell-poc

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

[POC] CVE-2026-66066 — KindaRails2Shell

CVE-2026-66066 + File Read, RCE, Scanner, Lab

[POC] CVE-2026-66066 — CVE-2026-66066-POC

PoC for CVE-2026-66066 in Ruby on Rails

[POC] CVE-2026-66066 — CVE-2026-66066

CVE-2026-66066

[POC] CVE-2026-66066 — rails-activestorage-vips-audit

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails and libvips versions and block-untrusted mitigations

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free