CVE-2026-5973

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.
References
Link Resource
https://github.com/FoundationAgents/MetaGPT/ Product
https://github.com/FoundationAgents/MetaGPT/issues/1930 Exploit Issue Tracking Mitigation
https://github.com/FoundationAgents/MetaGPT/pull/1983 Issue Tracking Patch
https://vuldb.com/submit/791755 Exploit Third Party Advisory VDB Entry
https://vuldb.com/vuln/356527 Third Party Advisory VDB Entry
https://vuldb.com/vuln/356527/cti Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-09 20:16

Updated : 2026-06-17 10:59


NVD link : CVE-2026-5973

Mitre link : CVE-2026-5973

CVE.ORG link : CVE-2026-5973


JSON object : View

Products Affected

deepwisdom

  • metagpt
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')