CVE-2026-5974
HIGHA vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.
Published: 4/9/2026Modified: 4/29/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (6)
https://github.com/FoundationAgents/MetaGPT/Producthttps://github.com/FoundationAgents/MetaGPT/issues/1931Issue TrackingExploithttps://github.com/FoundationAgents/MetaGPT/pull/1940Issue TrackingPatchhttps://vuldb.com/submit/791758ExploitThird Party Advisoryhttps://vuldb.com/vuln/356528Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/356528/ctiPermissions Required