PT-2026-78837 · Pypi · Agno

·

CVE-2026-76832

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Agno (affected versions not specified)
Description PythonTools in libs/agno/agno/tools/python.py contains a path traversal issue. This occurs when parent-directory traversal sequences are supplied in the file name argument passed to the read file(), save to file(), or run python file() tool actions. Attackers can use direct tool invocation or prompt injection in agent-processed content to bypass the base dir boundary. This allows for arbitrary file read, arbitrary file write, or arbitrary Python code execution with the privileges of the process user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict the use of the file name argument in the read file(), save to file(), and run python file() functions to prevent the use of traversal sequences.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76832

Affected Products

Agno