CVE-2026-79408

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

Published 2026-08-31. Last modified 2026-09-01.