CVE-2026-6109Disclosure(deepwisdom / metagpt)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-352CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metagpt

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
metagpt

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-12: 2Technical Details · 2026-04-12: 204-12
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6109 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6109 #CVE-2026-6109 #CVE #Medium #CyberSecurity #InfoSec https://t.co/2QQTi46egO

    Post summary

    An announcement of CVE-2026-6109 with medium risk (severity 4.3) and no further exploitation or patch details.

    0000026
    125 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6109 Cross-Site Request Forgery in FoundationAgents MetaGPT Up To 0.8.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6109

    Post summary

    CVE-2026-6109 is a CSRF vulnerability affecting FoundationAgents MetaGPT up to 0.8.1, with details listed on vulmon.com.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdeepwisdommetagpt---

Explore more