All 5 CVE vulnerabilities found in agno, with AI-generated Chinese analysis, references, and POCs.
Vendor: agno-agi
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-76832 | Agno PythonTools Path Traversal via joinpath file_name argument CWE-22 | 8.8 | High | 2026-08-19 |
| CVE-2026-10105 | agno 2.6.5 SQL Injection via ClickHouse delete_by_metadata() CWE-89 | 8.3 | High | 2026-05-29 |
| CVE-2026-35002 | Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution CWE-95 | 9.3 | Critical | 2026-04-02 |
| CVE-2025-64168 | Agno session state overwrites between different sessions/users CWE-362 | 7.1 | High | 2025-10-31 |
| CVE-2025-8665 | agno-agi agno Model Context Protocol mcp.py MultiMCPTools os command injection CWE-78 | 6.3 | Medium | 2025-08-06 |
All 5 known CVE vulnerabilities affecting agno with full Chinese analysis, references, and POCs where available.