Impact
Agno software up to and including version 2.5.8 is vulnerable to remote code execution because the PythonTools and ShellTools components accept large language model–generated arguments and pass them directly to native execution functions such as exec(), runpy.run_path(), and subprocess.run() without performing any sanitization. A malicious user who can embed commands into content processed by the agent—such as web pages or documents—can therefore cause arbitrary Python code and operating‑system command execution on the host server, leading to complete compromise of confidentiality, integrity, and availability.
Affected Systems
The affected product is Agno, with all releases up to and including 2.5.8 being impacted. No other vendors or product versions are listed as affected.
Risk and Exploitability
The vulnerability requires no authentication and is exploitable via content that the agent processes, which can be supplied by remote entities, making it potentially attractive to attackers. The CVSS score of 9.8 indicates a high severity, while the EPSS score of less than 1 % suggests a low but nonzero likelihood of exploitation. Because the issue is not listed in CISA’s KEV catalog, it may have slipped past many monitoring efforts, but the combination of a high CVSS and the absence of authentication makes it a very concerning risk for exposed deployments.
OpenCVE Enrichment