An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metagpt
Metagpt metagpt |
|
| Vendors & Products |
Metagpt
Metagpt metagpt |
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection via path Argument in MetaGPT 0.8.1 | |
| Weaknesses | CWE-78 |
Mon, 31 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-31T00:00:00.000Z
Updated: 2026-09-01T14:45:21.332Z
Reserved: 2026-08-25T00:00:00.000Z
Link: CVE-2026-79408
Updated: 2026-09-01T14:45:12.483Z
Status : Deferred
Published: 2026-08-31T21:17:49.017
Modified: 2026-09-01T21:00:36.830
Link: CVE-2026-79408
No data.