HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-5974 — A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affe...
·Source: NIST NVD
Updated:
Executive Summary
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.
Analysis
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. CVSS Score: 7.3. Published: 2026-04-09T20:16:29.347.