Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3ghp-8r47-4gj4 | FoundationAgents MetaGPT vulnerable to eval injection |
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deepwisdom
Deepwisdom metagpt |
|
| CPEs | cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Deepwisdom
Deepwisdom metagpt |
Mon, 13 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foundation Agents
Foundation Agents metagpt |
|
| Vendors & Products |
Foundation Agents
Foundation Agents metagpt |
Thu, 09 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. | |
| Title | FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection | |
| Weaknesses | CWE-94 CWE-95 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-13T20:14:17.735Z
Reserved: 2026-04-09T12:04:20.721Z
Link: CVE-2026-5971
Updated: 2026-04-13T20:14:13.475Z
Status : Analyzed
Published: 2026-04-09T18:17:04.723
Modified: 2026-04-29T19:45:53.750
Link: CVE-2026-5971
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:31:46Z
Github GHSA