CVE-2026-35002
Critical · CVSS 9.8agno — eval() injection arbitrary code execution (CWE-95)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-95
Description
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.
Search profile — drives PoC discovery
Symbols field_typeeval()FunctionCallmodel execution componentagno-agi/agno
Keywords CVE-2026-35002agnoagno-agifield_type eval injectionFunctionCall arbitrary code executionPyPI agno RCEagno eval code executionagno 2.3.24
Versions: < 2.3.24
Affected packages
| PyPI | agno | 0 → 2.3.24 |
References
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z