CVE-2026-6109
MEDIUMFoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
Title source: cnaDescription
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
References (5)
Scores
CVSS v3
4.3
EPSS
0.0001
EPSS Percentile
0.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-352
CWE-862
Status
published
Products (3)
FoundationAgents/MetaGPT
0.8.0
FoundationAgents/MetaGPT
0.8.1
pypi/metagpt
0PyPI
Published
Apr 12, 2026
Tracked Since
Apr 12, 2026