Executive brief
FoundationAgents MetaGPT, a framework for multi-agent AI systems, contains a vulnerability that allows for unauthorized command execution. The software's terminal tool fails to properly restrict the types of commands an AI agent can run, allowing a remote attacker to execute arbitrary system commands. This could lead to full system compromise, data theft, or the installation of malicious software on the host machine.
Technical details
A command injection vulnerability exists in MetaGPT's `Terminal.run_command` function within `metagpt/tools/libs/terminal.py`. The implementation relies on a weak blocklist that only filters specific strings like 'run dev' and 'serve ', failing to sanitize or block dangerous shell operators or system commands. Because the `Terminal` class is registered as an LLM-callable tool, an attacker can use prompt injection to influence the LLM into executing arbitrary bash commands via `self.process.stdin.write`. This allows for remote code execution (RCE) with the privileges of the application process. The issue is addressed in version 0.8.2.
Affected products
- FoundationAgents MetaGPT <= 0.8.1
Timeline
- 2026-02-04: other: Vulnerability reported via GitHub Issue #1929
- 2026-04-09: advisory: GitHub Advisory and NVD entry published
- 2026-04-09: patched: Patch commit d04ffc8dc67903e8b327f78ec121df5e190ffc7b identified