CVE-2026-5974

HIGH

FoundationAgents MetaGPT terminal.py Bash.run os command injection

Title source: cna
STIX 2.1

Description

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-356528 | FoundationAgents MetaGPT terminal.py Bash.run os command injection
https://vuldb.com/vuln/356528
Signature, Permissions Required signature permissions-required
VDB-356528 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/356528/cti
Third Party Advisory third-party-advisory
Submit #791758 | FoundationAgents MetaGPT 0.8.1 OS Command Injection (CWE-78)
https://vuldb.com/submit/791758

Scores

CVSS v3 7.3
EPSS 0.0224
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (4)
deepwisdom/metagpt < 0.8.1
FoundationAgents/MetaGPT 0.8.0
FoundationAgents/MetaGPT 0.8.1
pypi/metagpt 0PyPI
Published Apr 09, 2026
Tracked Since Apr 10, 2026