CVE-2026-5973 is an OS command injection vulnerability in FoundationAgents MetaGPT versions up to 0.8.1, specifically within the get_mime_type function in metagpt/utils/common.py. This flaw allows attackers to execute arbitrary system commands on affected systems. The vulnerability requires no authentication or user interaction, making it accessible to any remote attacker with network connectivity. The vulnerability carries a CVSS score of 7.3 (High) with a network-based attack vector and low complexity, indicating it is straightforward to exploit remotely. Successful exploitation could result in unauthorized access, integrity compromise, and service disruption across confidentiality, integrity, and availability dimensions. The EPSS score of 0.018 suggests the actual exploitation risk is currently modest compared to the broader CVE landscape. Exploit code has been publicly disclosed, creating heightened risk for immediate weaponization. However, the vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation indicators. Notably, the project maintainers were notified early through a pull request but have not implemented a response, leaving users of affected versions without an official patch and increasing the window of exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.8.1CPE matchmatch criteria | cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.