UNKNOWN PyPI
Agno is vulnerable to Eval Injection
GHSA-77rh-m34w-rv36 · CVE-2026-35002 · PYSEC-2026-256
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-35002
- WEB https://github.com/agno-agi/agno/commit/cbf675521d4d2281925a051784a3b94172e56416
- PACKAGE https://github.com/agno-agi/agno
- WEB https://github.com/agno-agi/agno/releases/tag/v2.3.24
- WEB https://www.vulncheck.com/advisories/agno-field-type-eval-injection-arbitrary-code-execution
Ready to move
Start Securing
Free, no credit card | First findings in minutes