{"id":"PYSEC-2024-9","details":"MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.","aliases":["CVE-2024-23750","GHSA-g7ph-8423-pf4j"],"modified":"2026-06-10T17:01:25.028247388Z","published":"2024-01-22T01:15:00Z","references":[{"type":"REPORT","url":"https://github.com/geekan/MetaGPT/issues/731"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7ph-8423-pf4j"}],"affected":[{"package":{"name":"metagpt","ecosystem":"PyPI","purl":"pkg:pypi/metagpt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.5"}]}],"versions":["0.1","0.3.0","0.4.0","0.5.0","0.5.1","0.5.2","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/metagpt/PYSEC-2024-9.yaml"}}],"schema_version":"1.7.5"}