CVE-2026-5970

HIGH

FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection

Title source: cna
STIX 2.1

Description

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-356524 | FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
https://vuldb.com/vuln/356524
Signature, Permissions Required signature permissions-required
VDB-356524 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/356524/cti
Third Party Advisory third-party-advisory
Submit #791693 | FoundationAgents MetaGPT 0.8.1 Code Injection (CWE-94)
https://vuldb.com/submit/791693

Scores

CVSS v3 7.3
EPSS 0.0039
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-94
Status published
Products (4)
deepwisdom/metagpt < 0.8.1
FoundationAgents/MetaGPT 0.8.0
FoundationAgents/MetaGPT 0.8.1
pypi/metagpt 0 - 0.8.1PyPI
Published Apr 09, 2026
Tracked Since Apr 09, 2026