Impact
Foundation Agents MetaGPT contains a flaw in its deserialize_message function that fails to validate data before deserialization. This allows an attacker to send a specially crafted payload that is processed as trusted data, resulting in arbitrary code execution with the privileges of the service account. No authentication is required for exploitation.
Affected Systems
The vulnerability is confirmed in Foundation Agents MetaGPT version 0.8.1. Earlier releases are not explicitly listed as affected, but the deserialization routine has not been changed prior to 0.8.1, so those versions might also be vulnerable.
Risk and Exploitability
The CVSS base score of 9.8 marks the flaw as critical. The EPSS score of less than 1 percent indicates a low current likelihood of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. Because authentication is not required, the threat vector is remote over the network, allowing any host that can reach the service endpoint to launch the exploit.
OpenCVE Enrichment