Skip to content
agnoGHSA-82m5-3pcp-hccq

agno contains a SQL injection vulnerability

High8.3CVE-2026-10105 · Published May 29, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
agno
PyPI
<= 2.6.5No fix yet
Details and references

agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete all rows, target specific rows, or extract information through error-based or blind SQL injection techniques.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-89
Also known as
CVE-2026-10105, PYSEC-2026-2333

More agno advisories

All
DateAdvisory
Apr 2Agno is vulnerable to Eval Injection
CVE-2026-35002Criticalfixed in 2.3.24
Oct 312025Agno session state overwrites between different sessions/users
CVE-2025-64168High7.1fixed in 2.2.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.