MetaGPT has an eval injection in metagpt/strategy/tot.py
Moderate severity
GitHub Reviewed
Published
Apr 12, 2026
to the GitHub Advisory Database
•
Updated Apr 14, 2026
Description
Published by the National Vulnerability Database
Apr 12, 2026
Published to the GitHub Advisory Database
Apr 12, 2026
Reviewed
Apr 14, 2026
Last updated
Apr 14, 2026
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References