mediumCVSS 7.3Vulnerability

CVE-2026-6110

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
medium
summary
MetaGPT has an eval injection in metagpt/strategy/tot.py
epss_score
0.00409
cvss_score
7.3
ghsa_published
2026-04-12T03:30:25Z
source_url
https://github.com/advisories/GHSA-xr7v-m9px-q4qj
ghsa_updated
2026-04-14T20:04:10Z
ghsa_id
GHSA-xr7v-m9px-q4qj
cve_id
CVE-2026-6110
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.33897

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/metagpt

AFFECTS (1)

[Software]pip/metagpt

Explore deeper with Ninja Signal's threat intelligence graph