mediumCVSS 7.3Vulnerability

CVE-2026-5973

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.

Properties

severity
medium
summary
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
epss_score
0.02283
cvss_score
7.3
ghsa_published
2026-04-09T21:31:30Z
source_url
https://github.com/advisories/GHSA-qw5f-qpq5-ppfg
ghsa_updated
2026-04-10T20:27:59Z
ghsa_id
GHSA-qw5f-qpq5-ppfg
cve_id
CVE-2026-5973
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.81676

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/metagpt

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]pip/metagpt

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5973 (CVSS 7.3) — Ninja Signal Threat Intelligence | Ninja Signal