CVE-2026-76832
- EPSS 0.84%
- Veröffentlicht 19.08.2026 21:58:51
- Zuletzt bearbeitet 20.08.2026 16:18:20
Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_f...
CVE-2026-10105
- EPSS 0.32%
- Veröffentlicht 29.05.2026 16:18:19
- Zuletzt bearbeitet 21.07.2026 15:10:00
agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can ex...
CVE-2026-35002
- EPSS 0.84%
- Veröffentlicht 02.04.2026 14:34:14
- Zuletzt bearbeitet 24.07.2026 21:10:00
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence...