CodeChron[verified]@ChronCodePatch
The post notes an upgrade to the agno library to fix a critical eval‑injection CVE, without mentioning PoCs, exploits, or active attacks.
CodeChron[verified]@ChronCodePatch
The update to the `agno` library (v2.x) replaces v1.x to mitigate a critical eval injection vulnerability (CVE‑2026‑35002).
CodeChron[verified]@ChronCodePatch
The tweet announces a pull request that upgrades the travel planner agent to Agno 2.x to mitigate CVE-2026-35002, presenting a patch rather than an exploit or active threat.
CCB Alert@CCBalertDisclosure
The post announces a critical CVE-2026-35002 affecting Agno before 2.3.24, highlighting arbitrary Python code execution with a high CVSS of 9.3, but provides no PoC, exploit, or patch details.
Autumn Good@autumn_good_35Disclosure
The advisory announces CVE-2026-35002 in Agno (<2.3.24) as an eval injection that enables arbitrary code execution, but it provides no PoC, exploit tool, active exploitation evidence, patch, or debunking information.
PulsePatch.io@pulsepatchioDisclosure
A newly disclosed CVE‑2026‑35002 (Eval injection) in Agno could allow remote code execution, but no evidence of active exploitation, patch, or PoC is present.
CVE@CVEnewDisclosure
The text discloses that Agno versions prior to 2.3.24 suffer from an arbitrary code execution flaw allowing attackers to run arbitrary Python code.
0day Signal@0dayPublishingDisclosure
The post discloses a critical Python RCE vulnerability in the Agno field_type parameter, highlighting its exploitation potential without indicating active attacks or available mitigations.