CVE-2026-5973: FoundationAgents MetaGPT common.py get_mime_type os command injection
Published Apr 9, 2026
·Updated
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function getmimetype of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.
Affected Software
2 affected components
pip/metagpt<=0.8.1
Deepwisdom Metagpt<=0.8.1
Remediation
Patch Available
Event History
Apr 9, 2026
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyAffected Software
Advisory Published
via GitHub·09:31 PM
Data Sourced
via GitHub·09:31 PM
DescriptionSeverityWeaknessAffected Software
Jul 20, 58298
Event
via FIRST·09:55 PM