CVE-2026-6110

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:deepwisdom:metagpt:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:deepwisdom:metagpt:0.8.1:*:*:*:*:*:*:*

History

30 Apr 2026, 14:55

Type Values Removed Values Added
References () https://github.com/FoundationAgents/MetaGPT/ - () https://github.com/FoundationAgents/MetaGPT/ - Product
References () https://github.com/FoundationAgents/MetaGPT/issues/1933 - () https://github.com/FoundationAgents/MetaGPT/issues/1933 - Issue Tracking
References () https://github.com/FoundationAgents/MetaGPT/pull/1946 - () https://github.com/FoundationAgents/MetaGPT/pull/1946 - Issue Tracking, Patch
References () https://vuldb.com/submit/791761 - () https://vuldb.com/submit/791761 - Exploit, Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356970 - () https://vuldb.com/vuln/356970 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356970/cti - () https://vuldb.com/vuln/356970/cti - Permissions Required
First Time Deepwisdom metagpt
Deepwisdom
CPE cpe:2.3:a:deepwisdom:metagpt:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:deepwisdom:metagpt:0.8.0:*:*:*:*:*:*:*

12 Apr 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-12 03:16

Updated : 2026-04-30 14:55


NVD link : CVE-2026-6110

Mitre link : CVE-2026-6110

CVE.ORG link : CVE-2026-6110


JSON object : View

Products Affected

deepwisdom

  • metagpt
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')