CVE-2026-35002Critical· 9.8▾ MidnightAgno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.
agno < 2.3.24Upgrade past the affected range:
agno 2.3.24Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10105High· 8.3agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method
CVE-2025-64168High· 7.1Agno session state overwrites between different sessions/users
CVE-2026-85486High· 8.6Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation
CVE-2026-105315Medium· 4.7A vulnerability has been found in django-haystack up to 3.3.0
CVE-2026-55094High· 8.7Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes
CVE-2026-69662Low· 3.7The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.