CVE-2026-6110 is a code injection vulnerability affecting FoundationAgents MetaGPT versions up to 0.8.1, specifically in the generate_thoughts function of the Tree-of-Thought Solver component (metagpt/strategy/tot.py). The flaw permits remote code injection attacks without requiring authentication or user interaction. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector and low complexity, meaning any unauthenticated attacker can exploit it remotely. The impact is moderate, potentially compromising confidentiality, integrity, and availability of affected systems. The EPSS score of 0.00068 indicates this is not yet among the most frequently targeted vulnerabilities in the wild. Exploitation status shows the vulnerability has public exploit code available and poses an active risk, though there is no current indication of widespread exploitation in the KEV catalog. The affected project was notified through an issue report but has not yet responded, suggesting remediation efforts may be delayed. Organizations running MetaGPT should prioritize updating to patched versions or implementing compensating controls.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.0CPE matchmatch criteria | cpe:2.3:a:deepwisdom:metagpt:0.8.0:*:*:*:*:*:*:* | ||
0.8.1CPE matchmatch criteria | cpe:2.3:a:deepwisdom:metagpt:0.8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.