Impact
A flaw in FoundationAgents MetaGPT versions up to 0.8.2 allows a local attacker to manipulate an internal function, leading to arbitrary code injection. The defect is classified under CWE-74 for command injection and CWE-94 for code injection, meaning the attacker can run any commands or execute any code on the host system, compromising confidentiality, integrity, and availability.
Affected Systems
The affected product is FoundationAgents MetaGPT, specifically all releases up to and including 0.8.2. Users that run local instances of MetaGPT without applying the latest updates are susceptible.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been reported yet. However, the publicly available exploit and the requirement for local access mean that any user with local credentials on a MetaGPT host faces a realistic threat if the software remains unpatched. The vendor’s lack of response to the disclosure further elevates the risk.
OpenCVE Enrichment