CVE-2026-6111: FoundationAgents MetaGPT common.py decode_image server-side request forgery
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decodeimage of the file metagpt/utils/common.py. The manipulation of the argument imgurlorb64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Other sources
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.2. This impacts the function decodeimage of the file metagpt/utils/common.py. The manipulation of the argument imgurlorb64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6111?
The severity of CVE-2026-6111 is medium with a score of 5.3.
How do I fix CVE-2026-6111?
To fix CVE-2026-6111, you need to apply the available patch provided by the FoundationAgents MetaGPT repository.
What type of vulnerability is CVE-2026-6111?
CVE-2026-6111 is a server-side request forgery (SSRF) vulnerability.
What software is affected by CVE-2026-6111?
CVE-2026-6111 affects FoundationAgents MetaGPT and Deepwisdom Metagpt software versions up to 0.8.1.
Can CVE-2026-6111 be exploited remotely?
Yes, CVE-2026-6111 can be exploited remotely due to the nature of the server-side request forgery vulnerability.