Code Injection Vulnerability in FoundationAgents MetaGPT Application
CVE-2026-19058
Key Information:
- Vendor
Foundationagents
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-19058?
A vulnerability exists in FoundationAgents MetaGPT versions up to 0.8.2, specifically within the DataInterpreter function located in the data_interpreter.py file. This flaw allows for code injection attacks initiated from a local position, potentially compromising system integrity. The exploit has been publicly disclosed and demonstrates an urgent need for remediation. Despite early notification to the vendor, no response has been provided regarding the vulnerability.
Affected Version(s)
MetaGPT 0.8.0
MetaGPT 0.8.1
MetaGPT 0.8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
