Agno PythonTools path traversal vulnerability CVE-2026-76832
A path traversal vulnerability in Agno's PythonTools allows attackers to read, write, or execute arbitrary files by injecting directory traversal sequences through the file_name argument. The vulnerability can be exploited via direct tool invocation or prompt injection in agent-processed content.
Disclosed 19 August 2026 · Record updated 13 September 2026
Impact
Arbitrary file read, write, and Python code execution within process user authority
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-76832
