Sceawere
Vulnerability Detail
CVE-2026-19060UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MetaGPT Code Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 1d ago
- Vendor
- FoundationAgents
- Product
- MetaGPT
- Attack Type
- Code Injection
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-06T22:16:53.070Z",
"pubdate": "2026-08-06T22:16:53.070Z",
"executiveSummary": "A vulnerability has been identified in FoundationAgents MetaGPT up to version 0.8.2, specifically involving an unspecified function that allows for code injection. This security flaw enables a local attacker to execute arbitrary code within the context of the affected application, leading to potential system compromise, unauthorized data access, or privilege escalation. The scope of impact encompasses all deployments running vulnerable versions of the MetaGPT product. Risk implications are severe due to the availability of a public exploit, increasing the likelihood of active exploitation in real-world environments. The vendor was notified of the vulnerability prior to public disclosure but failed to provide any response or official patch, leaving systems exposed. Exploitation requires local access to the target host and the ability to interact with the vulnerable component, meaning an adversary must already possess a foothold on the underlying operating system or local execution privileges to successfully mount the attack vector.",
"technicalDetails": "The vulnerability resides in FoundationAgents MetaGPT up to version 0.8.2 within an undisclosed function that improperly handles user-supplied input or environmental data, leading directly to a code injection weakness. The root cause stems from the insecure evaluation, parsing, or execution of dynamic data streams without adequate sanitization, validation, or structural isolation. Because the affected function fails to safely process inputs, an attacker capable of manipulating local execution parameters can inject malicious payloads designed to be interpreted and executed by the underlying execution engine or interpreter.\nThe attack flow requires the adversary to operate locally on the target machine hosting the vulnerable MetaGPT instance. Given that local access is a prerequisite, the threat actor leverages existing local privileges to supply crafted input payloads to the vulnerable function. Upon processing the malicious input, the application fails to restrict execution boundaries, allowing the injected code to execute with the privileges of the user running the MetaGPT process. Depending on the runtime environment and application permissions, successful execution of the injected payload can result in full system compromise, arbitrary command execution, data exfiltration, or lateral movement within the local infrastructure.\nThe attack vector does not require network exposure, authentication bypasses, or remote interaction, as the vulnerability is constrained to local exploitation vectors. Affected versions include all releases of FoundationAgents MetaGPT up to and including version 0.8.2. Post-exploitation impact is dictated by the permission level of the running MetaGPT instance, potentially granting the attacker persistence on the host system or access to sensitive configuration files, API keys, and internal data structures managed by the agent framework."
}