Skip to content
agnoGHSA-77rh-m34w-rv36

Agno is vulnerable to Eval Injection

CriticalCVE-2026-35002 · Published Apr 2, 2026 · updated Jun 29, 2026

Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.

GitHub advisory

Affected versions

PackageAffectedFixed in
agno
PyPI
< 2.3.242.3.24
Details and references

More agno advisories

All agno
Advisory
agno contains a SQL injection vulnerability
High8.3May 29
Agno session state overwrites between different sessions/users
High7.1Oct 31, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.