VDB
Sign up
HIGH7.3

PYSEC-2026-2640

MetaGPT has an Injection issue

Details

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/metagpt
Introduced in: 0

No fixed version published yet for metagpt (pip). Pin to a known-safe version or switch to an alternative.

References