CVE-2026-37003: Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to exe...
Added to the CISA Known Exploited Vulnerabilities catalog on 27 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.
Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execution sinks including exec(), runpy.run_path(), and subprocess.run(). An unauthenticated attacker c...
Required action: Review and patch if applicable to your AI infrastructure.