CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-35002

Critical · CVSS 9.8

agno — eval() injection arbitrary code execution (CWE-95)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-95

Description

Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.

Search profile — drives PoC discovery

Symbols field_typeeval()FunctionCallmodel execution componentagno-agi/agno
Keywords CVE-2026-35002agnoagno-agifield_type eval injectionFunctionCall arbitrary code executionPyPI agno RCEagno eval code executionagno 2.3.24
Versions: < 2.3.24

Affected packages

PyPI agno 0 → 2.3.24

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z