CVE-2026-6111

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://github.com/FoundationAgents/MetaGPT/ Product
https://github.com/FoundationAgents/MetaGPT/issues/1934 Issue Tracking
https://github.com/FoundationAgents/MetaGPT/pull/1941 Issue Tracking Patch
https://vuldb.com/submit/791762 Exploit Third Party Advisory VDB Entry
https://vuldb.com/vuln/356971 Third Party Advisory VDB Entry
https://vuldb.com/vuln/356971/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:deepwisdom:metagpt:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:deepwisdom:metagpt:0.8.1:*:*:*:*:*:*:*

History

30 Apr 2026, 14:49

Type Values Removed Values Added
CPE cpe:2.3:a:deepwisdom:metagpt:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:deepwisdom:metagpt:0.8.0:*:*:*:*:*:*:*
First Time Deepwisdom metagpt
Deepwisdom
References () https://github.com/FoundationAgents/MetaGPT/ - () https://github.com/FoundationAgents/MetaGPT/ - Product
References () https://github.com/FoundationAgents/MetaGPT/issues/1934 - () https://github.com/FoundationAgents/MetaGPT/issues/1934 - Issue Tracking
References () https://github.com/FoundationAgents/MetaGPT/pull/1941 - () https://github.com/FoundationAgents/MetaGPT/pull/1941 - Issue Tracking, Patch
References () https://vuldb.com/submit/791762 - () https://vuldb.com/submit/791762 - Exploit, Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356971 - () https://vuldb.com/vuln/356971 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356971/cti - () https://vuldb.com/vuln/356971/cti - Permissions Required, VDB Entry

12 Apr 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-12 03:16

Updated : 2026-04-30 14:49


NVD link : CVE-2026-6111

Mitre link : CVE-2026-6111

CVE.ORG link : CVE-2026-6111


JSON object : View

Products Affected

deepwisdom

  • metagpt
CWE
CWE-918

Server-Side Request Forgery (SSRF)