← Vulnerability feed

Vulnerability record · CVE-2026-5971 · published 9 April 2026

CVE-2026-5971: Deepwisdom metagpt code injection vulnerability

Deepwisdom · Metagpt

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

5.5 CVSS 4.0 Medium EPSS 0.71% · top 48.3% CWE-94 · Code injectionCWE-95 · CWE-95
5.5CVSS 4.0 base score, v2 7.5
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-5971 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-0760Deepwisdom metagpt deserialization of untrusted data vulnerabilityFoundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote…EPSS 1.3%9.8CVE-2026-0761Deepwisdom metagpt code injection vulnerabilityFoundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers …EPSS 2.4%8.8CVE-2024-23750Deepwisdom metagpt code injection vulnerabilityMetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Pop…EPSS 0.97%6.9CVE-2026-5974Deepwisdom metagpt command injection vulnerabilityA vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/li…EPSS 3.5%5.5CVE-2026-6110Deepwisdom metagpt injection vulnerabilityA vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.…EPSS 0.71%5.5CVE-2026-5973Deepwisdom metagpt command injection vulnerabilityA vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The ma…EPSS 3.5%5.5CVE-2026-5972Deepwisdom metagpt command injection vulnerabilityA vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/t…EPSS 3.5%5.5CVE-2026-5970Deepwisdom metagpt injection vulnerabilityA vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MB…EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2026-5971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.