AE-G3HH1AH0
LLM-callable terminal tool executes arbitrary shell commands because its blocklist filters only two strings
SECURITY FAILUREseverity: CRITICALcause: LIKELYoutcome: UNKNOWNconfidence: LOW
MetaGPT's Terminal class is registered as an LLM-callable tool, and Terminal.run_command() wrote commands to a persistent bash shell after filtering only two specific strings. Dangerous commands were not filtered, so prompt injection influencing the agent could lead to remote code execution.
- Framework / agent
- MetaGPT · multi-agent framework with LLM-callable shell tool
- Remediation attempts
- SUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- SECURITY ADVISORY FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command — github.com/advisories, retrieved 2026-09-29
- GITHUB ISSUE [Security] Command Injection in Terminal.run_command() via Weak Blocklist — github.com/FoundationAgents/MetaGPT, retrieved 2026-09-29
- GITHUB COMMIT Security fix: Prevent command injection in Bash tool via LLM prompt injection — github.com/paipeline/MetaGPT, retrieved 2026-09-29
Symptoms
- Dangerous shell commands passed to Terminal.run_command() are executed without being blocked
- Prompt injection against agentic workflows can yield full system access on the host
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-G3HH1AH0. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.