VYPR
Vendor

MetaGPT

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2026-79408CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

  • CVE-2024-23750HigJan 22, 2024
    risk 0.57cvss 8.8epss 0.01

    MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.

  • CVE-2026-79407HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME…

  • CVE-2026-19060MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early…

  • CVE-2026-19059LowAug 6, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be…