Junglewise Threat Intelligence

CVE-2026-5972: FoundationAgents MetaGPT OS command injection in Terminal.run_command

CVE-2026-5972 · Severity: high · CVSS 7.3 · Published 2026-04-09

Technologies: FoundationAgents Metagpt, metagpt (PyPI). Vendors: PyPI.

Executive brief

FoundationAgents MetaGPT, a framework for multi-agent AI systems, contains a vulnerability that allows for unauthorized command execution. The software's terminal tool fails to properly restrict the types of commands an AI agent can run, allowing a remote attacker to execute arbitrary system commands. This could lead to full system compromise, data theft, or the installation of malicious software on the host machine.

Technical details

A command injection vulnerability exists in MetaGPT's `Terminal.run_command` function within `metagpt/tools/libs/terminal.py`. The implementation relies on a weak blocklist that only filters specific strings like 'run dev' and 'serve ', failing to sanitize or block dangerous shell operators or system commands. Because the `Terminal` class is registered as an LLM-callable tool, an attacker can use prompt injection to influence the LLM into executing arbitrary bash commands via `self.process.stdin.write`. This allows for remote code execution (RCE) with the privileges of the application process. The issue is addressed in version 0.8.2.

Affected products

  • FoundationAgents MetaGPT <= 0.8.1

Timeline

  • 2026-02-04: other: Vulnerability reported via GitHub Issue #1929
  • 2026-04-09: advisory: GitHub Advisory and NVD entry published
  • 2026-04-09: patched: Patch commit d04ffc8dc67903e8b327f78ec121df5e190ffc7b identified

References

Related threats