Description
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.
Problem types
Product status
0.8.1
Timeline
| 2026-04-09: | Advisory disclosed |
| 2026-04-09: | VulDB entry created |
| 2026-04-09: | VulDB entry last update |
Credits
Eric-d (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/356528 (VDB-356528 | FoundationAgents MetaGPT terminal.py Bash.run os command injection)
vuldb.com/vuln/356528/cti (VDB-356528 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/791758 (Submit #791758 | FoundationAgents MetaGPT 0.8.1 OS Command Injection (CWE-78))
github.com/FoundationAgents/MetaGPT/issues/1931
github.com/FoundationAgents/MetaGPT/pull/1940
github.com/FoundationAgents/MetaGPT/