Impact
An Agno installation running version 2.5.8 or earlier is vulnerable because the PythonTools and ShellTools components pass LLM‑generated arguments directly to execution sinks such as exec(), runpy.run_path(), and subprocess.run() without sanitization. An unauthenticated attacker can embed malicious instructions into any content processed by the agent – for example, web pages or documents – allowing arbitrary Python code and OS command execution on the host server. The impact is total compromise of confidentiality, integrity, and availability for the affected system.
Affected Systems
The affected product is Agno, versions up to 2.5.8 inclusive. No other vendor or product versions are listed as impacted.
Risk and Exploitability
The exploit requires only an unauthenticated ability to supply content that the agent will process, implying that the attack can be performed from remote sources that can deliver content to the server. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, yet the lack of an authentication requirement and the presence of unfiltered system calls indicate a high severity and reasonable likelihood that attackers will attempt exploitation if the platform is exposed.
OpenCVE Enrichment