CVE-2026-5974Disclosure(deepwisdom / metagpt)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metagpt

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
metagpt

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-09: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-19: 104-0904-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 HIGH Severity CVE-2026-5974 | CVSS 7.3 OS Command Injection in FoundationAgents MetaGPT ≤0.8.1 Affected: Bash[.]run function in metagpt/tools/libs/terminal[.]py Remotely exploitable, no auth required Vendor unresponsive to disclosure #CVE #Vulnerability #PatchNow https://t.co/O22agWGCkW

    Post summary

    High severity OS command injection in MetaGPT 0.8.1 allows remote unauthenticated exploitation; vendor unresponsive.

    0000049
    26 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5974 A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function http://Bash.run in the library metagpt/tools/libs/terminal.py. Thi… https://www.cve.org/CVERecord?id=CVE-2026-5974

    Post summary

    The text announces CVE-2026-5974, a vulnerability in FoundationAgents MetaGPT 0.8.1 affecting the Bash.run function in terminal.py.

    0000090
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdeepwisdommetagpt---

Explore more