External risk intelligence

Remote Code Execution in agentscope via RealtimeAgent execute_python_code tool.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51856

The vulnerability exists in an agent-based framework where the RealtimeAgent component processes WebSocket connections. Because RealtimeAgent sessions are commonly designed to be internet-facing or exposed via APIs to facilitate interactive, remote user communication, this creates a likely surface for public-internet access in real-world agentic service deployments.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in the agentscope framework that could allow a remote user to execute arbitrary Python code within the service environment. The issue arises when the RealtimeAgent's Python code execution tool is exposed without proper authorization or isolation, potentially leading to unauthorized actions on the system.

  • Remote code execution in agent framework.
  • Matters because it could compromise the service environment.
  • Focus on confirming if this framework is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by sending a specially crafted message over a WebSocket connection to a vulnerable agent. This message would trick the agent into executing arbitrary Python code within its service environment, bypassing necessary security checks. The consequence of this successful attack could be a complete compromise of the service.

  • Remote network access required.
  • Agent calls tool without approval.
  • Complete service compromise possible.

Live Threat

Current exploitation, exposure, and threat context

A remote user could execute arbitrary Python code within the service environment when the `execute_python_code` tool is exposed by the `RealtimeAgent` session. This could occur if the agent is configured to allow direct calls to this tool without further user approval or specific isolation measures, potentially impacting the integrity and availability of the service.

  • Service environment code execution.
  • User prompts agent to call tool.
  • Compromise of service environment.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability, as it affects an agentic framework that executes Python code remotely. The first practical step is to identify all instances of the affected technology, confirm their exposure and criticality, and then assign an accountable owner to plan remediation.

  • Identify accountable application/platform owners.
  • Verify agent reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is agentscope and how is it used?

Agentscope is a framework designed for building multi-agent systems, which are sets of automated programs that interact to solve tasks. Developers use it to create interactive agents that can perform complex workflows by utilizing various tools and communicating over network protocols like WebSockets to assist with real-time operations.

What does CVE-2026-51856 mean for my system?

This vulnerability is classified as CWE-94, or Improper Control of Generation of Code. It means that the software lacks the necessary safeguards to distinguish between legitimate instructions and malicious ones when processing tool calls. Specifically, it allows an unauthorized user to trick the agent into running arbitrary Python code within the host environment.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending a crafted WebSocket message that prompts the RealtimeAgent to invoke its Python execution tool. The bug is specifically present when the agent is configured to use this tool automatically. If the agent is not configured to expose this specific tool or requires an approval step before tool invocation, the attack path is not present.

Do I need to worry about this if my agent is internal?

Halo Surface Signal indicates this issue is likely relevant for your environment if the RealtimeAgent is exposed to the public internet for interactive, remote communication. If your agentic services are strictly internal, the risk is lower, though you should verify if the RealtimeAgent component is accessible to any untrusted network segments.

When should I take action for this vulnerability?

You should begin by auditing your deployments to identify if you are running agentscope versions 1.0.18 or 1.0.19. Once identified, confirm whether your RealtimeAgent sessions are configured to expose the execute_python_code tool. If this tool is active, coordinate with your engineering team to establish access controls or implement isolation measures immediately.

References