Agno Remote Code Execution via Prompt Injection
Agno up to version 2.5.8 is vulnerable to remote code execution through prompt injection in PythonTools and ShellTools components. An unauthenticated attacker can exploit unsanitized LLM-generated arguments to execute arbitrary code and OS commands.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Remote code execution and arbitrary OS command execution on host servers via prompt injection in agent tools
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-37003
