Description
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Product status
0.8.1
Timeline
| 2026-04-11: | Advisory disclosed |
| 2026-04-11: | VulDB entry created |
| 2026-04-11: | VulDB entry last update |
Credits
Eric-d (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/356969 (VDB-356969 | FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery)
vuldb.com/vuln/356969/cti (VDB-356969 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/791759 (Submit #791759 | FoundationAgents MetaGPT 0.8.1 Cross Site Request Forgery (CWE-352))
github.com/FoundationAgents/MetaGPT/issues/1932
github.com/FoundationAgents/MetaGPT/