PT-2026-26920 · Foundation Agents · Metagpt
Goku
+1
·
Published
2026-03-21
·
Updated
2026-03-21
·
CVE-2026-4516
CVSS v3.1
6.3
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write analysis code.py of the component DataInterpreter. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Exploit
Fix
Special Elements Injection
Improper Neutralization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Metagpt