lowCVSS 6.3Vulnerability

CVE-2026-6111

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Properties

summary
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
severity
low
epss_score
0.00263
cvss_score
6.3
ghsa_published
2026-04-12T03:30:26Z
source_url
https://github.com/advisories/GHSA-r5v8-c28h-f8r8
ghsa_updated
2026-04-14T20:04:20Z
ghsa_id
GHSA-r5v8-c28h-f8r8
cve_id
CVE-2026-6111
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.17831

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/metagpt

AFFECTS (1)

[Software]pip/metagpt

Explore deeper with Ninja Signal's threat intelligence graph