Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
agno 2.6.5 SQL Injection via ClickHouse delete_by_metadata()
Vulnerability Description
agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete all rows, target specific rows, or extract information through error-based or blind SQL injection techniques.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
agno SQL注入漏洞
Vulnerability Description
agno是Agno开源的一个用于构建具有内存、知识和推理的多智能体系统的全栈框架。 agno 2.6.5版本存在SQL注入漏洞,该漏洞源于ClickHouse向量数据库后端存在SQL注入,可能导致攻击者通过delete_by_metadata方法注入任意SQL表达式。
CVSS Information
N/A
Vulnerability Type
N/A