deepwisdom records
13 published records for vendor deepwisdom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 15.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-0761No exploit | Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerabilitydeepwisdom · metagpt · CWE-94 | Critical9.8 | — | 2.4% | Jan 23, 2026 |
39Monitor | CVE-2026-0760No exploit | Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerabilitydeepwisdom · metagpt · CWE-502 | Critical9.8 | — | 1.3% | Jan 23, 2026 |
35Monitor | CVE-2024-23750No exploit | MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprdeepwisdom · metagpt · CWE-94 | High8.8 | — | 1.0% | Jan 21, 2024 |
28Monitor | CVE-2026-5974No exploit | FoundationAgents MetaGPT terminal.py Bash.run os command injectiondeepwisdom · metagpt · CWE-77 | Medium6.9 | — | 3.5% | Apr 9, 2026 |
23Monitor | CVE-2026-5972No exploit | FoundationAgents MetaGPT terminal.py Terminal.run_command os command injectiondeepwisdom · metagpt · CWE-77 | Medium5.5 | — | 3.5% | Apr 9, 2026 |
23Monitor | CVE-2026-5973No exploit | FoundationAgents MetaGPT common.py get_mime_type os command injectiondeepwisdom · metagpt · CWE-77 | Medium5.5 | — | 3.5% | Apr 9, 2026 |
22Monitor | CVE-2026-5971No exploit | FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injectiondeepwisdom · metagpt · CWE-94 | Medium5.5 | — | 0.7% | Apr 9, 2026 |
22Monitor | CVE-2026-5970No exploit | FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injectiondeepwisdom · metagpt · CWE-74 | Medium5.5 | — | 0.7% | Apr 9, 2026 |
22Monitor | CVE-2026-6110No exploit | FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injectiondeepwisdom · metagpt · CWE-74 | Medium5.5 | — | 0.7% | Apr 11, 2026 |
8Monitor | CVE-2026-4515No exploit | Foundation Agents MetaGPT operator.py code_generate code injectiondeepwisdom · metagpt · CWE-74 | Low2.1 | — | 0.4% | Mar 21, 2026 |
8Monitor | CVE-2026-4516No exploit | Foundation Agents MetaGPT DataInterpreter write_analysis_code.py injectiondeepwisdom · metagpt · CWE-74 | Low2.1 | — | 0.4% | Mar 21, 2026 |
8Monitor | CVE-2026-6111Proof of concept | FoundationAgents MetaGPT common.py decode_image server-side request forgerydeepwisdom · metagpt · CWE-918 | Low2.1 | — | 0.4% | Apr 11, 2026 |
8Monitor | CVE-2026-6109No exploit | FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgerydeepwisdom · metagpt · CWE-352 | Low2.1 | — | 0.3% | Apr 11, 2026 |
- CVE-2026-076140Plan
Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%deepwisdom · metagptJan 23, 2026
- CVE-2026-076039Monitor
Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%deepwisdom · metagptJan 23, 2026
- CVE-2024-2375035Monitor
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subpr
HighCVSS 8.8No exploitEPSS 1%deepwisdom · metagptJan 21, 2024
- CVE-2026-597428Monitor
FoundationAgents MetaGPT terminal.py Bash.run os command injection
MediumCVSS 6.9No exploitEPSS 3%deepwisdom · metagptApr 9, 2026
- CVE-2026-597223Monitor
FoundationAgents MetaGPT terminal.py Terminal.run_command os command injection
MediumCVSS 5.5No exploitEPSS 3%deepwisdom · metagptApr 9, 2026
- CVE-2026-597323Monitor
FoundationAgents MetaGPT common.py get_mime_type os command injection
MediumCVSS 5.5No exploitEPSS 3%deepwisdom · metagptApr 9, 2026
- CVE-2026-597122Monitor
FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection
MediumCVSS 5.5No exploitEPSS 1%deepwisdom · metagptApr 9, 2026
- CVE-2026-597022Monitor
FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
MediumCVSS 5.5No exploitEPSS 1%deepwisdom · metagptApr 9, 2026
- CVE-2026-611022Monitor
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
MediumCVSS 5.5No exploitEPSS 1%deepwisdom · metagptApr 11, 2026
- CVE-2026-45158Monitor
Foundation Agents MetaGPT operator.py code_generate code injection
LowCVSS 2.1No exploitEPSS 0%deepwisdom · metagptMar 21, 2026
- CVE-2026-45168Monitor
Foundation Agents MetaGPT DataInterpreter write_analysis_code.py injection
LowCVSS 2.1No exploitEPSS 0%deepwisdom · metagptMar 21, 2026
- CVE-2026-61118Monitor
FoundationAgents MetaGPT common.py decode_image server-side request forgery
LowCVSS 2.1Proof of conceptEPSS 0%deepwisdom · metagptApr 11, 2026
- CVE-2026-61098Monitor
FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
LowCVSS 2.1No exploitEPSS 0%deepwisdom · metagptApr 11, 2026