A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2, impacting an unknown function and leading to code injection. The attack requires local access, and the exploit is publicly available. Users should verify affected systems and monitor for suspicious activity. Evidence is limited; primary official records indicate a local code injection vulnerability in FoundationAgents MetaGPT up to 0. [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.903Z and has not been modified since then. The vulnerability, CVE-2026-19059, was determined in FoundationAgents MetaGPT up to 0.8.2, affecting the read function in metagpt/tools/libs/editor.py, leading to path traversal. The attack requires local access, and the exploit has been publicl [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.730Z and has not been modified since then. CVE-2026-19058 is a local code injection vulnerability in FoundationAgents MetaGPT up to 0.8.2. The vulnerability is located in the DataInterpreter function of metagpt/roles/di/data_interpreter.py and requires local access to be exploited. The a [truncated]
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/utils/common.py. This manipulation of the argument mermaid.path causes command injection. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult.