---
id: CVE-2026-5973
aliases:
  - GHSA-qw5f-qpq5-ppfg
  - PYSEC-2026-2641
title: >-
  FoundationAgents MetaGPT vulnerable to OS Command Injection in
  metagpt/utils/common.py
summary: >-
  FoundationAgents MetaGPT vulnerable to OS Command Injection in
  metagpt/utils/common.py
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
vendor: metagpt
product: metagpt
ecosystem: pip
affected:
  - metagpt <= 0.8.1
published: '2026-04-09'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-qw5f-qpq5-ppfg'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5973'
  - url: 'https://github.com/FoundationAgents/MetaGPT/issues/1930'
  - url: 'https://github.com/FoundationAgents/MetaGPT/pull/1983'
  - url: 'https://github.com/FoundationAgents/MetaGPT'
  - url: 'https://vuldb.com/submit/791755'
  - url: 'https://vuldb.com/vuln/356527'
  - url: 'https://vuldb.com/vuln/356527/cti'
tags:
  - osv
  - pip
epss: 0.03456
epssPercentile: 0.8857
ingestedAt: '2026-07-13T18:58:02.303Z'
---

## Overview

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.

## Affected packages

- `metagpt <= 0.8.1`

## Remediation

Refer to the advisory for the patched release.
