A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Applying a patch is the recommended action to fix this issue.
CVE-2026-5972 is an OS command injection vulnerability in MetaGPT versions up to 0.8.1 affecting the Terminal.run_command function, allowing remote code execution. The vulnerability exists in metagpt/tools/libs/terminal.py and has been publicly disclosed with a known patch available.
ثغرة حقن أوامر نظام التشغيل في مكتبة MetaGPT تسمح للمهاجمين بتنفيذ أوامر نظام تعسفية عن بعد من خلال دالة Terminal.run_command. تم الكشف عن الثغرة علناً وقد تُستخدم في هجمات فعلية، مع توفر رقعة أمان معروفة.
This is an OS command injection flaw in MetaGPT up to version 0.8.1 that enables remote attackers to execute arbitrary system commands. The vulnerability affects the Terminal.run_command function and has been publicly disclosed with a patch available.
Immediately upgrade MetaGPT to version 0.8.2 or later that includes patch d04ffc8dc67903e8b327f78ec121df5e190ffc7b. Review and restrict access to systems running MetaGPT, implement input validation and sanitization for all command parameters, and monitor for suspicious command execution patterns.
قم بترقية MetaGPT فوراً إلى الإصدار 0.8.2 أو أحدث الذي يتضمن الرقعة d04ffc8dc67903e8b327f78ec121df5e190ffc7b. راجع وقيّد الوصول إلى الأنظمة التي تعمل بـ MetaGPT، وطبّق التحقق من صحة المدخلات وتنظيفها لجميع معاملات الأوامر، ومراقبة أنماط تنفيذ الأوامر المريبة.