Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcc8-4q7h-wvwc

Опубликовано: 09 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.3

Описание

FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

Пакеты

Наименование

metagpt

pip
Затронутые версииВерсия исправления

<= 0.8.1

Отсутствует

EPSS

Процентиль: 81%
0.02241
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 7.3
nvd
5 месяцев назад

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

EPSS

Процентиль: 81%
0.02241
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-77