PT-2026-68665 · Foundation Agents · Metagpt

·

CVE-2026-19058

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions FoundationAgents MetaGPT versions prior to 0.8.3
Description A code injection issue exists in the DataInterpreter() function within the metagpt/roles/di/data interpreter.py file. This flaw allows a local attacker to execute arbitrary code through manipulation of the function.
Recommendations As a temporary workaround, restrict access to the DataInterpreter() function in the metagpt/roles/di/data interpreter.py file to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19058

Affected Products

Metagpt