CVE-2026-19060

Summary

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
FoundationAgentsMetaGPT0.8.0affected
FoundationAgentsMetaGPT0.8.1affected
FoundationAgentsMetaGPT0.8.2affected

Weaknesses

  • CWE-94: Code Injection
  • CWE-74: Injection

References