{"id":"CVE-2026-5970","aliases":["GHSA-g977-h85w-h2xj","PYSEC-2026-2640"],"url":"https://o3.security/vulnerability/CVE-2026-5970","summary":"FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection","details":"A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.","published":"2026-04-09T17:00:21.409Z","modified":"2026-08-07T11:31:25.242377990Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"metagpt","fixedVersion":null}],"fix":{"url":"https://github.com/FoundationAgents/MetaGPT/pull/1988","label":"FoundationAgents/MetaGPT#1988"},"references":[{"type":"WEB","url":"https://github.com/FoundationAgents/MetaGPT/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5970.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5970"},{"type":"ADVISORY","url":"https://vuldb.com/submit/791693"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/356524"},{"type":"REPORT","url":"https://github.com/FoundationAgents/MetaGPT/issues/1942"},{"type":"REPORT","url":"https://vuldb.com/vuln/356524/cti"},{"type":"FIX","url":"https://github.com/FoundationAgents/MetaGPT/pull/1988"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:25.242377990Z"}}