PT-2026-47177 · Foundation Agents · Metagpt
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
FoundationAgents MetaGPT versions prior to 0.8.3
Description
Command injection is possible via the
mermaid.path argument in the check cmd exists() function located in the metagpt/utils/common.py file. This issue allows a remote attacker to execute arbitrary commands, although the attack requires a high degree of complexity and is considered difficult to exploit.Recommendations
Update to a version later than 0.8.2.
As a temporary workaround, restrict or avoid the use of the
mermaid.path argument within the check cmd exists() function.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Metagpt