CVE-2024-23750: Code Injection
Published Jan 22, 2024
·Updated
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.runscript() passes shell metacharacters to subprocess.Popen.
Affected Software
2 affected components
Deepwisdom Metagpt<=0.6.4
pip/metagpt>=0<=0.6.6
Event History
Jan 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-23750?
CVE-2024-23750 is considered a high-severity vulnerability due to the ability to execute arbitrary code.
2
How do I fix CVE-2024-23750?
To fix CVE-2024-23750, update the MetaGPT software to version 0.6.5 or later.
3
Who is affected by CVE-2024-23750?
CVE-2024-23750 affects users of MetaGPT versions up to 0.6.4.
4
What is the attack vector for CVE-2024-23750?
The attack vector for CVE-2024-23750 involves exploiting the QaEngineer role to execute arbitrary code through RunCode.run_script().
5
What systems are impacted by CVE-2024-23750?
CVE-2024-23750 impacts systems using MetaGPT available through pip and Deepwisdom's distribution up to version 0.6.4.