CVE-2026-6110 | FoundationAgents MetaGPT up to 0.8.1 Tree-of-Thought Solver metagpt/strategy/tot.py generate_thoughts code injection (Issue 1933 / EUVD-2026-21696)
A vulnerability marked as critical has been reported in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection.
This vulnerability is traded as CVE-2026-6110. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.