Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5973

32
FAUCET Score

CVE-2026-5973 is an OS command injection vulnerability in FoundationAgents MetaGPT versions up to 0.8.1, specifically within the get_mime_type function in metagpt/utils/common.py. This flaw allows attackers to execute arbitrary system commands on affected systems. The vulnerability requires no authentication or user interaction, making it accessible to any remote attacker with network connectivity. The vulnerability carries a CVSS score of 7.3 (High) with a network-based attack vector and low complexity, indicating it is straightforward to exploit remotely. Successful exploitation could result in unauthorized access, integrity compromise, and service disruption across confidentiality, integrity, and availability dimensions. The EPSS score of 0.018 suggests the actual exploitation risk is currently modest compared to the broader CVE landscape. Exploit code has been publicly disclosed, creating heightened risk for immediate weaponization. However, the vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation indicators. Notably, the project maintainers were notified early through a pull request but have not implemented a response, leaving users of affected versions without an official patch and increasing the window of exposure.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.8.1CPE matchmatch criteria
cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
2.28%
Probability of exploitation in next 30 days
EPSS Percentile
81.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0228 is in the 71st percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

pipGHSA-qw5f-qpq5-ppfgmedium

FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py

Apr 9, 2026

References

github.com / FoundationAgents/MetaGPT
Product
github.com / FoundationAgents/MetaGPT/issues/1930
ExploitIssue TrackingMitigation
github.com / FoundationAgents/MetaGPT/pull/1983
Issue TrackingPatch
vuldb.com / submit/791755
ExploitThird Party AdvisoryVDB Entry
vuldb.com / vuln/356527
Third Party AdvisoryVDB Entry
vuldb.com / vuln/356527/cti
Permissions Required