CVE-2026-5973

HIGH

FoundationAgents MetaGPT common.py get_mime_type os command injection

Title source: cna
STIX 2.1

Description

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-356527 | FoundationAgents MetaGPT common.py get_mime_type os command injection
https://vuldb.com/vuln/356527
Signature, Permissions Required signature permissions-required
VDB-356527 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/356527/cti
Third Party Advisory third-party-advisory
Submit #791755 | FoundationAgents MetaGPT 0.8.1 OS Command Injection (CWE-78)
https://vuldb.com/submit/791755

Scores

CVSS v3 7.3
EPSS 0.0228
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (4)
deepwisdom/metagpt < 0.8.1
FoundationAgents/MetaGPT 0.8.0
FoundationAgents/MetaGPT 0.8.1
pypi/metagpt 0PyPI
Published Apr 09, 2026
Tracked Since Apr 10, 2026