CVE-2026-6109Medium· 4.3▾ SunlitMetaGPT has an eval injection via a cross-site request forgery attack
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
metagpt <= 0.8.2Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6110High· 7.3MetaGPT has an eval injection in metagpt/strategy/tot.py
CVE-2026-5972High· 7.3FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
CVE-2026-6111Medium· 6.3MetaGPT affected by server-side request forgery in metagpt/utils/common.py
CVE-2026-5973High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
CVE-2026-5970High· 7.3MetaGPT has an Injection issue
CVE-2026-5974High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py