A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foundation Agents
Foundation Agents metagpt |
|
| Vendors & Products |
Foundation Agents
Foundation Agents metagpt |
Sun, 12 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery | |
| Weaknesses | CWE-352 CWE-862 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-04-12T01:30:15.439Z
Updated: 2026-04-12T01:30:15.439Z
Reserved: 2026-04-11T07:49:27.735Z
Link: CVE-2026-6109
No data.
Status : Awaiting Analysis
Published: 2026-04-12T02:16:00.790
Modified: 2026-04-13T15:01:43.663
Link: CVE-2026-6109
No data.