CVE-2026-6109: FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Other sources
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6109?
The severity of CVE-2026-6109 is classified as medium with a score of 5.3.
How do I fix CVE-2026-6109?
To fix CVE-2026-6109, update to the latest version of FoundationAgents MetaGPT, ensuring you are using a version greater than 0.8.1.
What type of vulnerability is CVE-2026-6109?
CVE-2026-6109 is a cross-site request forgery (CSRF) vulnerability.
What impact does CVE-2026-6109 have on users?
CVE-2026-6109 could allow attackers to manipulate requests on behalf of a legitimate user, potentially compromising user data.
Which software is affected by CVE-2026-6109?
CVE-2026-6109 affects FoundationAgents MetaGPT versions up to 0.8.1.