mediumCVSS 7.3Vulnerability

CVE-2026-5972

A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue.

Properties

severity
medium
summary
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
epss_score
0.02328
cvss_score
7.3
ghsa_published
2026-04-09T21:31:30Z
source_url
https://github.com/advisories/GHSA-wp29-qmvj-frvp
ghsa_updated
2026-04-10T20:34:28Z
ghsa_id
GHSA-wp29-qmvj-frvp
cve_id
CVE-2026-5972
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.82068

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/metagpt

AFFECTS (1)

[Software]pip/metagpt

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5972 (CVSS 7.3) — Ninja Signal Threat Intelligence | Ninja Signal