← Vulnerability feed

Vulnerability record · CVE-2026-5974 · published 9 April 2026

CVE-2026-5974: Deepwisdom metagpt command injection vulnerability

Deepwisdom · Metagpt

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

6.9 CVSS 4.0 Medium EPSS 3.5% · top 11.4% CWE-77 · Command injectionCWE-78 · OS command injection
6.9CVSS 4.0 base score, v2 7.5
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-5974 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-0760Deepwisdom metagpt deserialization of untrusted data vulnerabilityFoundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote…EPSS 1.3%9.8CVE-2026-0761Deepwisdom metagpt code injection vulnerabilityFoundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers …EPSS 2.4%8.8CVE-2024-23750Deepwisdom metagpt code injection vulnerabilityMetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Pop…EPSS 0.97%5.5CVE-2026-6110Deepwisdom metagpt injection vulnerabilityA vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.…EPSS 0.71%5.5CVE-2026-5973Deepwisdom metagpt command injection vulnerabilityA vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The ma…EPSS 3.5%5.5CVE-2026-5972Deepwisdom metagpt command injection vulnerabilityA vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/t…EPSS 3.5%5.5CVE-2026-5970Deepwisdom metagpt injection vulnerabilityA vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MB…EPSS 0.71%5.5CVE-2026-5971Deepwisdom metagpt code injection vulnerabilityA flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/action…EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2026-5974), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.