CVE-2026-19060: FoundationAgents MetaGPT code injection
Published Aug 6, 2026
·Updated
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
FoundationAgents MetaGPT<=0.8.2
Event History
Aug 6, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19060?
The severity of CVE-2026-19060 is classified as medium with a score of 5.3.
2
How do I fix CVE-2026-19060?
To fix CVE-2026-19060, users should update FoundationAgents MetaGPT to version 0.8.3 or later.
3
What type of vulnerability is CVE-2026-19060?
CVE-2026-19060 is a code injection vulnerability.
4
What are the attack requirements for CVE-2026-19060?
CVE-2026-19060 requires local access for exploitation.
5
Is there a known exploit for CVE-2026-19060?
Yes, an exploit for CVE-2026-19060 is publicly available.