FoundationAgents MetaGPT code injection
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 4.8epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
FoundationAgents · MetaGPTpublic PoCs found — 1
cve_referencegist.github.com/tchen200311/3a3bff5a9613dd309db93e4c15079fc6unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://gist.github.com/tchen200311/3a3bff5a9613dd309db93e4c15079fc6https://gist.github.com/tchen200311/fe1acfbaa29652429309c2dad1aa2aedhttps://vuldb.com/cve/CVE-2026-19060https://vuldb.com/submit/864279https://vuldb.com/submit/864282https://vuldb.com/vuln/386517https://vuldb.com/vuln/386517/cti