{"schema_version":1,"title":"metagpt (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in metagpt (PyPI): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-5970, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-metagpt","json_url":"https://junglewise.ai/threats/technologies/pypi-metagpt.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-metagpt","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":10,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":9},"latest":[{"cve":"CVE-2026-5970","cvss":3.1,"epss":0.0071,"slug":"cve-2026-5970-metagpt-has-an-injection-issue","title":"PYSEC-2026-2640 - MetaGPT has an Injection issue","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:50.505415+00:00","url":"https://junglewise.ai/threats/cve-2026-5970-metagpt-has-an-injection-issue"},{"cve":"CVE-2026-10566","cvss":5.3,"epss":0.0012,"slug":"cve-2026-10566-foundationagents-metagpt-unsafe-deserialization-in-message-check","title":"FoundationAgents MetaGPT unsafe deserialization in Message.check_instruct_content","severity":"medium","exploited":false,"published_at":"2026-06-02T03:16:16.21+00:00","url":"https://junglewise.ai/threats/cve-2026-10566-foundationagents-metagpt-unsafe-deserialization-in-message-check"},{"cve":"CVE-2026-6111","cvss":6.3,"epss":0.0037,"slug":"cve-2026-6111-foundationagents-metagpt-ssrf-in-decode-image","title":"FoundationAgents MetaGPT SSRF in decode_image","severity":"medium","exploited":false,"published_at":"2026-04-12T03:16:08.827+00:00","url":"https://junglewise.ai/threats/cve-2026-6111-foundationagents-metagpt-ssrf-in-decode-image"},{"cve":"CVE-2026-6110","cvss":7.3,"epss":0.0071,"slug":"cve-2026-6110-foundationagents-metagpt-code-injection-in-tree-of-thought-solver","title":"FoundationAgents MetaGPT code injection in Tree-of-Thought Solver","severity":"high","exploited":false,"published_at":"2026-04-12T03:16:08.63+00:00","url":"https://junglewise.ai/threats/cve-2026-6110-foundationagents-metagpt-code-injection-in-tree-of-thought-solver"},{"cve":"CVE-2026-6109","cvss":4.3,"epss":0.0029,"slug":"cve-2026-6109-foundationagents-metagpt-rce-via-csrf-in-mineflayer-http-api","title":"FoundationAgents MetaGPT RCE via CSRF in Mineflayer HTTP API","severity":"medium","exploited":false,"published_at":"2026-04-12T02:16:00.79+00:00","url":"https://junglewise.ai/threats/cve-2026-6109-foundationagents-metagpt-rce-via-csrf-in-mineflayer-http-api"},{"cve":"CVE-2026-5973","cvss":7.3,"epss":0.0346,"slug":"cve-2026-5973-foundationagents-metagpt-os-command-injection-in-get-mime-type","title":"FoundationAgents MetaGPT OS command injection in get_mime_type","severity":"high","exploited":false,"published_at":"2026-04-09T21:31:30+00:00","url":"https://junglewise.ai/threats/cve-2026-5973-foundationagents-metagpt-os-command-injection-in-get-mime-type"},{"cve":"CVE-2026-5972","cvss":7.3,"epss":0.0349,"slug":"cve-2026-5972-foundationagents-metagpt-os-command-injection-in-terminal-run","title":"FoundationAgents MetaGPT OS command injection in Terminal.run_command","severity":"high","exploited":false,"published_at":"2026-04-09T21:31:30+00:00","url":"https://junglewise.ai/threats/cve-2026-5972-foundationagents-metagpt-os-command-injection-in-terminal-run"},{"cve":"CVE-2026-5974","cvss":7.3,"epss":0.0346,"slug":"cve-2026-5974-foundationagents-metagpt-os-command-injection-in-bash-tool","title":"FoundationAgents MetaGPT OS command injection in Bash tool","severity":"high","exploited":false,"published_at":"2026-04-09T21:31:30+00:00","url":"https://junglewise.ai/threats/cve-2026-5974-foundationagents-metagpt-os-command-injection-in-bash-tool"},{"cve":"CVE-2026-5971","cvss":7.3,"epss":0.0071,"slug":"cve-2026-5971-foundationagents-metagpt-eval-injection-in-actionnode","title":"FoundationAgents MetaGPT eval injection in ActionNode","severity":"high","exploited":false,"published_at":"2026-04-09T18:31:28+00:00","url":"https://junglewise.ai/threats/cve-2026-5971-foundationagents-metagpt-eval-injection-in-actionnode"},{"cve":"CVE-2024-23750","cvss":3.1,"epss":0.0097,"slug":"cve-2024-23750-code-execution-in-metagpt","title":"PYSEC-2024-9 - MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subpr","severity":"low","exploited":false,"published_at":"2024-01-22T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-23750-code-execution-in-metagpt"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"metagpt (PyPI)","slug":"pypi-metagpt","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Framework for building multi-agent systems with support for role-based collaboration.","url":"https://junglewise.ai/threats/technologies/pypi-metagpt"},"most_severe":[{"cve":"CVE-2026-5972","cvss":7.3,"epss":0.0349,"slug":"cve-2026-5972-foundationagents-metagpt-os-command-injection-in-terminal-run","title":"FoundationAgents MetaGPT OS command injection in Terminal.run_command","severity":"high","exploited":false,"published_at":"2026-04-09T21:31:30+00:00","url":"https://junglewise.ai/threats/cve-2026-5972-foundationagents-metagpt-os-command-injection-in-terminal-run"},{"cve":"CVE-2026-5973","cvss":7.3,"epss":0.0346,"slug":"cve-2026-5973-foundationagents-metagpt-os-command-injection-in-get-mime-type","title":"FoundationAgents MetaGPT OS command injection in get_mime_type","severity":"high","exploited":false,"published_at":"2026-04-09T21:31:30+00:00","url":"https://junglewise.ai/threats/cve-2026-5973-foundationagents-metagpt-os-command-injection-in-get-mime-type"},{"cve":"CVE-2026-5974","cvss":7.3,"epss":0.0346,"slug":"cve-2026-5974-foundationagents-metagpt-os-command-injection-in-bash-tool","title":"FoundationAgents MetaGPT OS command injection in Bash tool","severity":"high","exploited":false,"published_at":"2026-04-09T21:31:30+00:00","url":"https://junglewise.ai/threats/cve-2026-5974-foundationagents-metagpt-os-command-injection-in-bash-tool"},{"cve":"CVE-2026-6110","cvss":7.3,"epss":0.0071,"slug":"cve-2026-6110-foundationagents-metagpt-code-injection-in-tree-of-thought-solver","title":"FoundationAgents MetaGPT code injection in Tree-of-Thought Solver","severity":"high","exploited":false,"published_at":"2026-04-12T03:16:08.63+00:00","url":"https://junglewise.ai/threats/cve-2026-6110-foundationagents-metagpt-code-injection-in-tree-of-thought-solver"},{"cve":"CVE-2026-5971","cvss":7.3,"epss":0.0071,"slug":"cve-2026-5971-foundationagents-metagpt-eval-injection-in-actionnode","title":"FoundationAgents MetaGPT eval injection in ActionNode","severity":"high","exploited":false,"published_at":"2026-04-09T18:31:28+00:00","url":"https://junglewise.ai/threats/cve-2026-5971-foundationagents-metagpt-eval-injection-in-actionnode"},{"cve":"CVE-2026-6111","cvss":6.3,"epss":0.0037,"slug":"cve-2026-6111-foundationagents-metagpt-ssrf-in-decode-image","title":"FoundationAgents MetaGPT SSRF in decode_image","severity":"medium","exploited":false,"published_at":"2026-04-12T03:16:08.827+00:00","url":"https://junglewise.ai/threats/cve-2026-6111-foundationagents-metagpt-ssrf-in-decode-image"},{"cve":"CVE-2026-10566","cvss":5.3,"epss":0.0012,"slug":"cve-2026-10566-foundationagents-metagpt-unsafe-deserialization-in-message-check","title":"FoundationAgents MetaGPT unsafe deserialization in Message.check_instruct_content","severity":"medium","exploited":false,"published_at":"2026-06-02T03:16:16.21+00:00","url":"https://junglewise.ai/threats/cve-2026-10566-foundationagents-metagpt-unsafe-deserialization-in-message-check"},{"cve":"CVE-2026-6109","cvss":4.3,"epss":0.0029,"slug":"cve-2026-6109-foundationagents-metagpt-rce-via-csrf-in-mineflayer-http-api","title":"FoundationAgents MetaGPT RCE via CSRF in Mineflayer HTTP API","severity":"medium","exploited":false,"published_at":"2026-04-12T02:16:00.79+00:00","url":"https://junglewise.ai/threats/cve-2026-6109-foundationagents-metagpt-rce-via-csrf-in-mineflayer-http-api"},{"cve":"CVE-2024-23750","cvss":3.1,"epss":0.0097,"slug":"cve-2024-23750-code-execution-in-metagpt","title":"PYSEC-2024-9 - MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subpr","severity":"low","exploited":false,"published_at":"2024-01-22T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-23750-code-execution-in-metagpt"},{"cve":"CVE-2026-5970","cvss":3.1,"epss":0.0071,"slug":"cve-2026-5970-metagpt-has-an-injection-issue","title":"PYSEC-2026-2640 - MetaGPT has an Injection issue","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:50.505415+00:00","url":"https://junglewise.ai/threats/cve-2026-5970-metagpt-has-an-injection-issue"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}