CVE-2026-79408

An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

  • Published Aug 31, 2026
  • CVSS 9.8 critical
  • 2.1% chance of exploitation in the next 30 days (EPSS)

CVE-2026-79408 at the National Vulnerability Database