What is CVE-2026-19058?
This vulnerability in FoundationAgents MetaGPT up to version 0.8.2 allows code injection via the `DataInterpreter` function in `metagpt/roles/di/data_interpreter.py`. It requires local access and the public exploit disclosure increases the risk. Users should immediately update to the latest version.
Azərbaycanca: Bu boşluq FoundationAgents MetaGPT platformasının 0.8.2 versiyasına qədər olan `DataInterpreter` funksiyasında kod inyeksiyasına imkan verir. Bu zəiflik yerli giriş tələb edir və istismar kodunun ictimaiyyətə açıqlanması riski artırır. İstifadəçilər dərhal platformanı ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: FoundationAgents
FAQ2
Which component of which platform does CVE-2026-19058 affect?
This vulnerability affects the `DataInterpreter` function of the FoundationAgents MetaGPT platform.
What should I do to protect against CVE-2026-19058?
Users should immediately update the platform to the latest version, as the exploit code is already publicly disclosed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.