Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MetaGPT — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in MetaGPT, with AI-generated Chinese analysis, references, and POCs.

This page provides vulnerability aggregation data for MetaGPT, an open-source framework that orchestrates multi-agent systems to perform complex tasks. It focuses on security weaknesses associated with this specific software product, covering common weakness types such as broken access control, injection flaws, and insecure defaults. The collection includes vulnerability records tracked within the past five years, ranging from major security advisories to minor bug fixes that have been disclosed by vendors or discovered by independent researchers. This timeframe ensures that historical trends and persistent issues are available for analysis alongside recent updates. Users can utilize this resource to track MetaGPT’s security posture over time by reviewing vendor advisories and patch releases. The data allows for a deeper understanding of specific weakness classes affecting the framework, helping developers identify patterns in how security flaws are introduced or resolved. Additionally, individuals can look up the complete vulnerability history of the product to assess the overall robustness of the codebase and understand the context of past incidents. This aggregated view supports informed decision-making for integration, auditing, and risk management purposes without requiring manual scanning of disparate sources. The content is structured to facilitate efficient retrieval of security-related information for stakeholders interested in the integrity and reliability of MetaGPT deployments.

Vendor: Foundation Agents

CVE IDTitleCVSSSeverityPublished
CVE-2026-19060 FoundationAgents MetaGPT code injection CWE-94 5.3 Medium2026-08-06
CVE-2026-19059 FoundationAgents MetaGPT editor.py read path traversal CWE-22 3.3 Low2026-08-06
CVE-2026-19058 FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection CWE-94 5.3 Medium2026-08-06
CVE-2026-11455 FoundationAgents MetaGPT common.py check_cmd_exists command injection CWE-77 5.0 Medium2026-06-07
CVE-2026-10566 FoundationAgents MetaGPT schema.py Message.check_instruct_content deserialization CWE-502 5.3 Medium2026-06-02
CVE-2026-6111 FoundationAgents MetaGPT common.py decode_image server-side request forgery CWE-918 6.3 Medium2026-04-12
CVE-2026-6110 FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection CWE-94 7.3 High2026-04-12
CVE-2026-6109 FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery CWE-352 4.3 Medium2026-04-12
CVE-2026-5974 FoundationAgents MetaGPT terminal.py Bash.run os command injection CWE-78 7.3 High2026-04-09
CVE-2026-5973 FoundationAgents MetaGPT common.py get_mime_type os command injection CWE-78 7.3 High2026-04-09
CVE-2026-5972 FoundationAgents MetaGPT terminal.py Terminal.run_command os command injection CWE-78 7.3 High2026-04-09
CVE-2026-5971 FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection CWE-95 7.3 High2026-04-09
CVE-2026-5970 FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection CWE-94 7.3 High2026-04-09
CVE-2026-4516 Foundation Agents MetaGPT DataInterpreter write_analysis_code.py injection CWE-74 6.3 Medium2026-03-21
CVE-2026-4515 Foundation Agents MetaGPT operator.py code_generate code injection CWE-94 6.3 Medium2026-03-21
CVE-2026-0761 Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability CWE-94 9.8 -2026-01-23
CVE-2026-0760 Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability CWE-502 9.8 -2026-01-23

All 17 known CVE vulnerabilities affecting MetaGPT with full Chinese analysis, references, and POCs where available.