Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Agno Remote Code Execution via Prompt Injection

Agno up to version 2.5.8 is vulnerable to remote code execution through prompt injection in PythonTools and ShellTools components. An unauthenticated attacker can exploit unsanitized LLM-generated arguments to execute arbitrary code and OS commands.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Remote code execution and arbitrary OS command execution on host servers via prompt injection in agent tools

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-37003