Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.1% | — | Deepwisdom MetagptAI | 31/8/2026 | 1/9/2026 | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. | |
| Aplazada | Alta (7.5) | 0.50% | — | Deepwisdom MetagptAI | 31/8/2026 | 8/9/2026 | A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME value with the settings directory and opens… | |
| Aplazada | Baja (1.9) | 0.20% | — | Deepwisdom MetagptAI | 6/8/2026 | 12/8/2026 | A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in… | |
| Aplazada | Baja (1.9) | 0.21% | — | Deepwisdom MetagptAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early… | |
| Aplazada | Baja (1.9) | 0.19% | — | Deepwisdom MetagptAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/data_interpreter.py. The manipulation results in code injection. The attack must be initiated from a local position. The exploit has been made public and could be used.… | |
| Aplazada | Baja (1.3) | 0.94% | — | Deepwisdom MetagptAI | 7/6/2026 | 23/7/2026 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/utils/common.py. This manipulation of the argument mermaid.path causes command injection. The attack may be initiated remotely. A high degree of complexity is needed for… | |
| Aplazada | Baja (1.9) | 0.12% | — | Deepwisdom MetagptAI | 2/6/2026 | 22/7/2026 | A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available… | |
| Analizada | Baja (2.1) | 0.37% | — | Deepwisdom Metagpt | 12/4/2026 | 17/6/2026 | A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to… | |
| Analizada | Media (5.5) | 0.71% | — | Deepwisdom Metagpt | 12/4/2026 | 17/6/2026 | A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available… | |
| Analizada | Baja (2.1) | 0.29% | — | Deepwisdom Metagpt | 12/4/2026 | 17/6/2026 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from… | |
| Analizada | Media (6.9) | 3.5% | — | Deepwisdom Metagpt | 9/4/2026 | 17/6/2026 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a… | |
| Analizada | Media (5.5) | 3.5% | — | Deepwisdom Metagpt | 9/4/2026 | 17/6/2026 | A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the… | |
| Analizada | Media (5.5) | 3.5% | — | Deepwisdom Metagpt | 9/4/2026 | 17/6/2026 | A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.5) | 0.71% | — | Deepwisdom Metagpt | 9/4/2026 | 17/6/2026 | A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code. The attack may be… | |
| Analizada | Media (5.5) | 0.71% | — | Deepwisdom Metagpt | 9/4/2026 | 17/6/2026 | A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was… | |
| Analizada | Baja (2.1) | 0.43% | — | Deepwisdom Metagpt | 21/3/2026 | 17/6/2026 | A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of the component DataInterpreter. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and… | |
| Analizada | Baja (2.1) | 0.43% | — | Deepwisdom Metagpt | 21/3/2026 | 17/6/2026 | A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/scripts/operator.py. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Crítica (9.8) | 2.4% | — | Deepwisdom Metagpt | 23/1/2026 | 17/6/2026 | Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Crítica (9.8) | 1.3% | — | Deepwisdom Metagpt | 23/1/2026 | 17/6/2026 | Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerability. The specific… | |
| Modificada | Alta (8.8) | 0.97% | — | Deepwisdom Metagpt | 22/1/2024 | 17/6/2026 | MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen. |