CVE-2026-6109

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://github.com/FoundationAgents/MetaGPT/ Product
https://github.com/FoundationAgents/MetaGPT/issues/1932 Issue Tracking Exploit Mitigation
https://vuldb.com/submit/791759 Exploit Third Party Advisory VDB Entry
https://vuldb.com/vuln/356969 Third Party Advisory VDB Entry
https://vuldb.com/vuln/356969/cti Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:*

History

29 Apr 2026, 18:46

Type Values Removed Values Added
CPE cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:*
References () https://github.com/FoundationAgents/MetaGPT/ - () https://github.com/FoundationAgents/MetaGPT/ - Product
References () https://github.com/FoundationAgents/MetaGPT/issues/1932 - () https://github.com/FoundationAgents/MetaGPT/issues/1932 - Issue Tracking, Exploit, Mitigation
References () https://vuldb.com/submit/791759 - () https://vuldb.com/submit/791759 - Exploit, Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356969 - () https://vuldb.com/vuln/356969 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356969/cti - () https://vuldb.com/vuln/356969/cti - Permissions Required
First Time Deepwisdom metagpt
Deepwisdom

12 Apr 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-12 02:16

Updated : 2026-04-29 18:46


NVD link : CVE-2026-6109

Mitre link : CVE-2026-6109

CVE.ORG link : CVE-2026-6109


JSON object : View

Products Affected

deepwisdom

  • metagpt
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization