CVE-2026-5974: FoundationAgents MetaGPT terminal.py Bash.run os command injection
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5974?
CVE-2026-5974 has a high severity rating due to its potential for os command injection vulnerabilities.
How do I fix CVE-2026-5974?
To fix CVE-2026-5974, update the FoundationAgents MetaGPT package to version 0.8.2 or later.
What versions are affected by CVE-2026-5974?
CVE-2026-5974 affects FoundationAgents MetaGPT versions up to and including 0.8.1.
What is the impact of CVE-2026-5974?
The impact of CVE-2026-5974 includes the possibility of unauthorized command execution on the host operating system.
Is CVE-2026-5974 remotely exploitable?
Yes, CVE-2026-5974 can be exploited remotely if an attacker can interact with the affected Bash.run function.