Skip to main content

Vendor/product archive

deepwisdom / metagpt CVEs

Beta · best-effort

13 CVEs tagged to deepwisdom / metagpt2 Critical, 1 High, 6 Medium, 4 Low, 0 Unrated.

CVE-2026-6111

Published Apr 12, 2026

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the ar…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-6110

Published Apr 12, 2026

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Th…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-6109

Published Apr 12, 2026

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/inde…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5974

Published Apr 9, 2026

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulat…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5973

Published Apr 9, 2026

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os comma…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5972

Published Apr 9, 2026

A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The man…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5971

Published Apr 9, 2026

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the compon…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5970

Published Apr 9, 2026

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a mani…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-4516

Published Mar 21, 2026

A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of the component…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-4515

Published Mar 21, 2026

A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/scripts/operator.py. The manipulatio…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-0761

Published Jan 23, 2026

Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0760

Published Jan 23, 2026

Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23750

Published Jan 22, 2024

MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1