Metrics
Affected Vendors & Products
Wed, 29 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deepwisdom
Deepwisdom metagpt |
|
| CPEs | cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Deepwisdom
Deepwisdom metagpt |
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foundation Agents
Foundation Agents metagpt |
|
| Vendors & Products |
Foundation Agents
Foundation Agents metagpt |
Thu, 09 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet. | |
| Title | FoundationAgents MetaGPT terminal.py Bash.run os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-09T20:17:26.123Z
Reserved: 2026-04-09T12:04:47.323Z
Link: CVE-2026-5974
No data.
Status : Analyzed
Published: 2026-04-09T20:16:29.347
Modified: 2026-04-29T18:47:14.113
Link: CVE-2026-5974
No data.