CVE-2026-6111Medium· 6.3▾ TwilightPoC availableMetaGPT affected by server-side request forgery in metagpt/utils/common.py
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
1 GitHub repo
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
metagpt <= 0.8.2Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6110High· 7.3MetaGPT has an eval injection in metagpt/strategy/tot.py
CVE-2026-5972High· 7.3FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
CVE-2026-6109Medium· 4.3MetaGPT has an eval injection via a cross-site request forgery attack
CVE-2026-5973High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
CVE-2026-5970High· 7.3MetaGPT has an Injection issue
CVE-2026-5974High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py