CVE-2026-79408
An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.
- Published Aug 31, 2026
- CVSS 9.8 critical
- 2.1% chance of exploitation in the next 30 days (EPSS)