metagpt
The Multi-Agent Framework
Activity
- Latest release
- 1y ago
- Total releases
- 30
- Cadence
- ~4 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Jul 13, 2023
| Version | Released | |
|---|---|---|
0.8.2
patch
4 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.8.1
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.13
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.12
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.11
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.8.0
minor
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.7
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.6
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.4
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.3
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.2
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.1
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.0
minor
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.10
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.9
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.8
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.7
patch
9 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.6
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.5
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.4
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.3
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.2
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.1
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.0
minor
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.2
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.1
patch
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.0
minor
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.0
minor
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.3.0
minor
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev | ||
0.1
initial
10 CVEs
CVE-2026-10566
PYSEC-2026-2637
GHSA-3c3g-7hwg-9qmr
Jul 13, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Medium
Local
Low
Low
None
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6111
PYSEC-2026-2642
GHSA-r5v8-c28h-f8r8
Jul 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Medium
Network
Low
Low
None
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6110
PYSEC-2026-2645
GHSA-xr7v-m9px-q4qj
Jul 13, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Medium
Network
Low
None
None
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-6109
PYSEC-2026-2643
GHSA-w287-wwhf-95vv
Jul 13, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Medium
Network
Low
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 18 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5974
PYSEC-2026-2639
GHSA-fcc8-4q7h-wvwc
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Medium
Network
Low
None
None
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5972
PYSEC-2026-2644
GHSA-wp29-qmvj-frvp
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Medium
Network
Low
None
None
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5973
PYSEC-2026-2641
GHSA-qw5f-qpq5-ppfg
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Medium
Network
Low
None
None
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5971
PYSEC-2026-2638
GHSA-3ghp-8r47-4gj4
Jul 13, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Medium
Network
Low
None
None
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5970
PYSEC-2026-2640
GHSA-g977-h85w-h2xj
Jul 13, 2026
MetaGPT has an Injection issue
Medium
Network
Low
None
None
A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
+ 17 more Show less
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.8.0
0.8.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-23750
GHSA-g7ph-8423-pf4j
PYSEC-2024-9
Jan 22, 2024
Code execution in metagpt
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. Affected versions
0.1
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
+ 1 more Show less
0.6.6
References Updated Feb 16, 2024 · Source: OSV.dev |