HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-5974 — A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affe...

·Source: NIST NVD

Updated:

Executive Summary

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

Analysis

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. CVSS Score: 7.3. Published: 2026-04-09T20:16:29.347.

Indicators of Compromise (1)

CVE (1)
CVE-2026-5974
Source Attribution

Originally published by NIST NVD on Apr 9, 2026. Verified by: NIST.

Related Threats