CVE-2026-5974
Severity CVSS v4.0:
MEDIUM
Type:
CWE-77
Command Injection
Publication date:
09/04/2026
Last modified:
29/04/2026
Description
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:* | 0.8.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



