Executive brief
FoundationAgents MetaGPT is a multi-agent framework used to build AI-driven software applications. A security flaw in how the system handles message data allows an attacker with local access to execute unauthorized commands on the host machine. This could lead to a full system compromise or unauthorized access to sensitive data processed by the AI agents.
Technical details
A deserialization vulnerability exists in FoundationAgents MetaGPT up to version 0.8.2 within the `Message.check_instruct_content` function in `metagpt/schema.py`. The root cause is the unsafe use of the `eval()` function in `metagpt/utils/serialize.py:actionoutput_str_to_mapping()`, which processes attacker-controlled strings during the mapping of message arguments. An attacker with the ability to influence serialized Message data (e.g., through local storage or recovery paths) can achieve arbitrary Python code execution. While the attack is restricted to local execution, a public exploit has been released. As of the advisory date, no official patch has been released by the maintainers.
Affected products
- FoundationAgents MetaGPT <= 0.8.2
Timeline
- 2026-05-13: disclosed: Issue reported to the maintainers via GitHub issue #2038
- 2026-06-02: advisory: Published to the GitHub Advisory Database and NVD