Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/metagpt

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/data_interpreter.py. The manipulation results in code injection. The attack must be initiated from a local position. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

CVE-2026-19059 is a path traversal vulnerability in FoundationAgents MetaGPT versions 0.8.0, 0.8.1, and 0.8.2. It affects the read function in the file metagpt/tools/libs/editor.py. The vulnerability requires local access to exploit and has been publicly disclosed. The vendor has not responded to the disclosure. The CVSS score is 4.8, indicating medium severity.

Join the discussion

CVE-2026-19058 is a code injection vulnerability in FoundationAgents MetaGPT versions 0.8.0, 0.8.1, and 0.8.2. It affects the DataInterpreter function in the file metagpt/roles/di/data_interpreter.py. The vulnerability requires local access to exploit and allows an attacker to inject code. The vendor has not responded to the disclosure, and no official patch or remediation is currently available. The CVSS score is 4.8, indicating a medium severity risk.

Join the discussion

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/utils/common.py. This manipulation of the argument mermaid.path causes command injection. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue.

Join the discussion

CVE-2026-0761 is a critical remote code execution vulnerability in Foundation Agents MetaGPT version 0.8.1. It stems from improper validation of user-supplied input in the actionoutput_str_to_mapping function, allowing unauthenticated attackers to execute arbitrary Python code. Exploitation requires no authentication or user interaction and can compromise confidentiality, integrity, and availability of affected systems. The vulnerability has a CVSS score of 9.8, indicating critical severity. Although no known exploits are currently in the wild, the flaw poses a significant risk to organizations running this software. European organizations using MetaGPT should prioritize patching or mitigating this issue. Countries with higher adoption of AI and automation tools, such as Germany, France, and the UK, are more likely to be impacted.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:pypi/metagpt
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses