CVE-2026-35002
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the fieldtype parameter passed to eval(). Attackers can influence the fieldtype value in a FunctionCall to achieve remote code execution.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2026-35002, https://github.com/agno-agi/agno/commit/cbf675521d4d2281925a051784a3b94172e56416, https://github.com/agno-agi/agno, https://github.com/agno-agi/agno/releases/tag/v2.3.24, https://www.vulncheck.com/advisories/agno-field-type-eval-injection-arbitrary-code-execution
