OS Command Injection Vulnerability in FoundationAgents MetaGPT Software
CVE-2026-5972
Key Information:
- Vendor
Foundationagents
- Status
- Vendor
- CVE Published:
- 9 April 2026
Badges
What is CVE-2026-5972?
A vulnerability in FoundationAgents MetaGPT versions up to 0.8.1 allows for os command injection through the Terminal.run_command function in metagpt/tools/libs/terminal.py. This flaw enables remote attackers to execute arbitrary commands, posing significant security risks. The exploit has been publicly disclosed, making systems using vulnerable versions susceptible to remote attacks. Applying the recommended patch (d04ffc8dc67903e8b327f78ec121df5e190ffc7b) is crucial to mitigate this vulnerability and secure your environment.
Affected Version(s)
MetaGPT 0.8.0
MetaGPT 0.8.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
