CVE-2026-5973High· 7.3▾ TwilightFoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.3%
2.3% → 2.5%
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.
metagpt <= 0.8.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6110High· 7.3MetaGPT has an eval injection in metagpt/strategy/tot.py
CVE-2026-5972High· 7.3FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
CVE-2026-6109Medium· 4.3MetaGPT has an eval injection via a cross-site request forgery attack
CVE-2026-6111Medium· 6.3MetaGPT affected by server-side request forgery in metagpt/utils/common.py
CVE-2026-5970High· 7.3MetaGPT has an Injection issue
CVE-2026-5974High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py