Executive brief
MetaGPT is a multi-agent framework used to build AI-driven software applications. A security flaw in how the system handles configuration settings for Mermaid (a diagramming tool) allows an attacker to execute unauthorized commands on the underlying server. This could lead to a complete system compromise, though the attack is complex to perform and requires some level of existing access.
Technical details
A command injection vulnerability exists in MetaGPT versions up to 0.8.2 within the `check_cmd_exists` function located in `metagpt/utils/common.py`. The vulnerability is rooted in the improper neutralization of the `mermaid.path` configuration argument, which is passed to a system shell without sufficient validation. A remote attacker with low privileges can exploit this by manipulating the path configuration to execute arbitrary system commands. While the attack vector is network-based, exploitation is considered difficult and requires a high degree of complexity. As of the advisory date, the project has been notified via an issue report but a formal patch has not been confirmed.
Affected products
- FoundationAgents MetaGPT up to 0.8.2
Timeline
- 2026-06-07: advisory: Initial disclosure via VulDB and NVD
- 2026-06-07: disclosed: Public exploit details shared via Notion and GitHub issues
References
- https://github.com/FoundationAgents/MetaGPT/
- https://github.com/FoundationAgents/MetaGPT/issues/2037
- https://vuldb.com/cve/CVE-2026-11455
- https://vuldb.com/submit/828206
- https://vuldb.com/vuln/369074
- https://vuldb.com/vuln/369074/cti
- https://www.notion.so/asuka39/MetaGPT-Command-Injection-via-Mermaid-path-Configuration-35fe35b8556880b29113c8c1b414a8b2?source=copy_link