Feed/CVE-2026-10566
CVE-2026-10566MEDIUMCVSS 5.3

FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()

Published Jun 2, 2026·Updated Jul 22, 2026

NVD Description

A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected Packages (1)

metagptPYPI
Fixed in = 0.8.2

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free