CVE-2026-19059: FoundationAgents MetaGPT editor.py read path traversal
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19059?
CVE-2026-19059 has a severity rating of low with a score of 3.3.
How do I fix CVE-2026-19059?
To mitigate CVE-2026-19059, ensure that you are using a version of FoundationAgents MetaGPT that is later than 0.8.2.
What kind of attack can be executed with CVE-2026-19059?
CVE-2026-19059 can be exploited through a local path traversal attack targeting the read function in the editor.py file.
What component is affected by CVE-2026-19059?
CVE-2026-19059 affects the function read in the file metagpt/tools/libs/editor.py of FoundationAgents MetaGPT.
Is the CVE-2026-19059 vulnerability publicly disclosed?
Yes, CVE-2026-19059 has been publicly disclosed and may be actively exploited.