metagpt vulnerabilities
CVEs whose affected-version data names the metagpt package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-10566Medium· 5.3FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
CVE-2026-6110High· 7.3MetaGPT has an eval injection in metagpt/strategy/tot.py
MetaGPT has an eval injection in metagpt/strategy/tot.py
CVE-2026-6109Medium· 4.3MetaGPT has an eval injection via a cross-site request forgery attack
MetaGPT has an eval injection via a cross-site request forgery attack
CVE-2026-6111Medium· 6.3PoCMetaGPT affected by server-side request forgery in metagpt/utils/common.py
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
CVE-2026-5972High· 7.3FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
CVE-2026-5973High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
CVE-2026-5970High· 7.3MetaGPT has an Injection issue
MetaGPT has an Injection issue
CVE-2026-5974High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
CVE-2026-5971High· 7.3FoundationAgents MetaGPT vulnerable to eval injection
FoundationAgents MetaGPT vulnerable to eval injection