VYPR

MetaGPT

by Foundation Agents

CVEs (8)

  • CVE-2026-0761CriJan 23, 2026
    risk 0.64cvss 9.8epss 0.01

    Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this…

  • CVE-2026-0760CriJan 23, 2026
    risk 0.64cvss 9.8epss 0.01

    Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to…

  • CVE-2026-4516MedMar 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of the component DataInterpreter. The manipulation results in injection. It is possible to launch the attack…

  • CVE-2026-4515MedMar 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/scripts/operator.py. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-19060MedAug 6, 2026
    risk 0.34cvss 5.3epss

    A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early…

  • CVE-2026-19058MedAug 6, 2026
    risk 0.34cvss 5.3epss

    A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/data_interpreter.py. The manipulation results in code injection. The attack must be initiated from a local position. The exploit…

  • CVE-2026-10566MedJun 2, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local…

  • CVE-2026-19059LowAug 6, 2026
    risk 0.21cvss 3.3epss

    A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be…