CVE-2026-4515 | Foundation Agents MetaGPT up to 0.8.1 operator.py code_generate code injection
A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. It has been rated as critical. This affects the function code_generate of the file metagpt/ext/aflow/scripts/operator.py. The manipulation leads to code injection.
This vulnerability is traded as CVE-2026-4515. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.