Executive brief
MetaGPT, an open-source multi-agent framework for AI development, contains a vulnerability in its Tree-of-Thought (ToT) solver component. This component is responsible for managing complex reasoning tasks by generating and evaluating multiple 'thoughts' or steps. An attacker can exploit this by providing malicious input that triggers the execution of arbitrary code on the system running the framework, potentially leading to full system compromise or unauthorized data access.
Technical details
A code injection vulnerability exists in MetaGPT versions up to and including 0.8.2 within the `generate_thoughts` function of `metagpt/strategy/tot.py`. The root cause is the use of Python's `eval()` function to parse responses from Large Language Models (LLMs) without prior sanitization or validation. An attacker can exploit this via prompt injection or by influencing the LLM's output to include malicious Python code, which is then executed by the framework. While a pull request (#1946) has been proposed to replace `eval()` with `json.loads()`, the advisory indicates the project had not officially responded or merged a fix at the time of publication. Exploitation can be achieved remotely if the application processes untrusted user input through the ToT solver.
Affected products
- FoundationAgents MetaGPT <= 0.8.2
Timeline
- 2026-02-20: other: Pull request #1946 submitted to fix the vulnerability
- 2026-04-12: advisory: GitHub Advisory published
- 2026-04-12: disclosed: CVE-2026-6110 published to NVD