---
id: CVE-2026-6109
aliases:
  - GHSA-w287-wwhf-95vv
  - PYSEC-2026-2643
title: MetaGPT has an eval injection via a cross-site request forgery attack
summary: MetaGPT has an eval injection via a cross-site request forgery attack
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
vendor: metagpt
product: metagpt
ecosystem: pip
affected:
  - metagpt <= 0.8.2
published: '2026-04-12'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-w287-wwhf-95vv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6109'
  - url: 'https://github.com/FoundationAgents/MetaGPT/issues/1932'
  - url: 'https://github.com/FoundationAgents/MetaGPT'
  - url: 'https://vuldb.com/submit/791759'
  - url: 'https://vuldb.com/vuln/356969'
  - url: 'https://vuldb.com/vuln/356969/cti'
tags:
  - osv
  - pip
epss: 0.00294
epssPercentile: 0.19672
ingestedAt: '2026-07-13T18:58:03.959Z'
---

## Overview

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

## Affected packages

- `metagpt <= 0.8.2`

## Remediation

Refer to the advisory for the patched release.
