lowCVSS 4.3Vulnerability

CVE-2026-6109

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Properties

summary
MetaGPT has an eval injection via a cross-site request forgery attack
severity
low
epss_score
0.00224
cvss_score
4.3
ghsa_published
2026-04-12T03:30:25Z
source_url
https://github.com/advisories/GHSA-w287-wwhf-95vv
ghsa_updated
2026-04-14T20:03:40Z
ghsa_id
GHSA-w287-wwhf-95vv
cve_id
CVE-2026-6109
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
is_ghsa_only
false
epss_percentile
0.12801

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Cross-Site Request Forgery (CSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/metagpt

AFFECTS (1)

[Software]pip/metagpt

Explore deeper with Ninja Signal's threat intelligence graph