CVE-2026-5971 is a code injection vulnerability affecting FoundationAgents MetaGPT versions up to 0.8.1, specifically in the XML Handler component's ActionNode.xml_fill function within metagpt/actions/action_node.py. The flaw allows improper neutralization of directives in dynamically evaluated code, which could enable attackers to inject and execute arbitrary code. This vulnerability has remote attack potential and requires no authentication or user interaction. The vulnerability carries a CVSS v3.1 score of 7.3 (HIGH) with a network-based attack vector, low complexity, and no privilege or user interaction requirements. Successful exploitation could result in confidentiality, integrity, and availability impacts, allowing attackers to compromise affected systems with relative ease. The EPSS score of 0.00068 indicates this threat is below average relative to other known vulnerabilities, though this may change as adoption increases. Exploit code has been publicly released and the vulnerability is technically exploitable in real-world scenarios. However, the vulnerability is not currently on active exploitation lists (KEV or Hot List status), suggesting limited real-world abuse at this time. The development team was notified early through a pull request but has not yet responded with a patch, leaving affected users vulnerable and dependent on manual mitigation measures until an official fix is released.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.8.1CPE matchmatch criteria | cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.