
[ZDI-26-026|CVE-2026-0760] (0Day) Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVSS 9.8; Credit: Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative) https://www.zerodayinitiative.com/advisories/ZDI-26-026/
Post summary
The advisory announces CVE‑2026‑0760, a 0-day remote code execution flaw in MetaGPT’s deserialize_message function with a CVSS score of 9.8; no PoC, exploitation evidence, or patch information is provided.
