Cross-Site Request Forgery Vulnerability in FoundationAgents MetaGPT
CVE-2026-6109
Key Information:
- Vendor
Foundationagents
- Status
- Vendor
- CVE Published:
- 12 April 2026
Badges
What is CVE-2026-6109?
A significant vulnerability exists in FoundationAgents' MetaGPT, specifically within the evaluateCode function located in the Mineflayer HTTP API. This flaw allows for cross-site request forgery attacks, potentially permitting malicious entities to manipulate requests without appropriate authorization. Triggering this vulnerability is achievable remotely, raising serious security concerns. Even though the issue was reported to the FoundationAgents team, there has been no acknowledgment or action taken to resolve it, putting users at risk of exploitation. Stay informed and take necessary precautions to secure your systems.
Affected Version(s)
MetaGPT 0.8.0
MetaGPT 0.8.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
