CVE-2026-35002Disclosure(agno / agno)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch agno agno systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agno

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-03)
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
agno

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-04-02: 2Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Mentions · 2026-05-03: 3Patch / Workaround · 2026-05-03: 3Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 1Technical Details · 2026-05-03: 204-0204-0304-0404-0605-03
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure2
2026-04-031
Disclosure1
2026-04-041
Disclosure1
2026-04-061
Disclosure1
2026-05-033
Patch3
Full discourse8 posts
  • CodeChron@ChronCode
    Patch

    💡 Developer Intent The developer's intent behind this change was to upgrade the AI travel planner agent team's `agno` library dependency from version 1.x to 2.x. This action was taken to address a critical eval injection vulnerability, identified as CVE-2026-35002. The upgrade necessitated refactoring existing agent configurations to align with the `agno` 2.x API, which included parameter renames and removals.

    Post summary

    The post notes an upgrade to the agno library to fix a critical eval‑injection CVE, without mentioning PoCs, exploits, or active attacks.

    1001061
    8 followersView on X
  • CodeChron@ChronCode
    Patch

    📌 Narrative Summary A recent pull request updated the `agno` library dependency for the AI travel planner agent team from version 1.x to 2.x. This upgrade primarily addresses a critical eval injection vulnerability, CVE-2026-35002. The change involved updating the `agno` dependency in `pyproject.toml` and adapting existing code to the new `agno` 2.x API. • Deprecated parameters like `show_tool_calls` and `success_criteria` were removed. • Parameters such as `add_datetime_to_instructions` were renamed to `add_datetime_to_context`. • `add_member_tools_to_system_message` became `add_member_tools_to_context`. • `enable_agentic_context` was renamed to `enable_agentic_state`. This change was implemented in a single commit and merged swiftly.

    Post summary

    The update to the `agno` library (v2.x) replaces v1.x to mitigate a critical eval injection vulnerability (CVE‑2026‑35002).

    1000061
    7 followersView on X
  • CodeChron@ChronCode
    Patch

    🐛 Upgrade travel planner agent team to agno 2.x (CVE-2026-35002) 📊 7 files • +6/-24 lines 🔗 https://github.com/Shubhamsaboo/awesome-llm-apps/pull/774 #CodeChron #bugfix #Shubhamsaboo #awesomellmapps #python https://t.co/RohySu2P7L

    Post summary

    The tweet announces a pull request that upgrades the travel planner agent to Agno 2.x to mitigate CVE-2026-35002, presenting a patch rather than an exploit or active threat.

    1000059
    7 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical arbitrary code execution vulnerability in #Agno version <2.3.24. CVE-2026-35002 CVSS: 9.3. This enables attackers to perform Python code execution. #Patch #Patch #Patch

    Post summary

    The post announces a critical CVE-2026-35002 affecting Agno before 2.3.24, highlighting arbitrary Python code execution with a high CVSS of 9.3, but provides no PoC, exploit, or patch details.

    00001251
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.』 CVE-2026-35002 Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution https://www.vulncheck.com/advisories/agno-field-type-eval-injection-arbitrary-code-execution

    Post summary

    The advisory announces CVE-2026-35002 in Agno (<2.3.24) as an eval injection that enables arbitrary code execution, but it provides no PoC, exploit tool, active exploitation evidence, patch, or debunking information.

    00000381
    6.8K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An Eval Injection vulnerability (CVE-2026-35002) affects the `Agno` product, potentially leading to remote code execution. Review input handling for dynamic code execution. #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-35002-agno-eval-injection

    Post summary

    A newly disclosed CVE‑2026‑35002 (Eval injection) in Agno could allow remote code execution, but no evidence of active exploitation, patch, or PoC is present.

    0000051
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35002 Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python cod… https://www.cve.org/CVERecord?id=CVE-2026-35002

    Post summary

    The text discloses that Agno versions prior to 2.3.24 suffer from an arbitrary code execution flaw allowing attackers to run arbitrary Python code.

    00000127
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35002: Agno field_type Eval Injection A... Direct eval() on user-controlled field_type parameter = instant Python RCE with zero auth required - classic textbook f... https://zerodaysignal.com/vulnerability/CVE-2026-35002 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses a critical Python RCE vulnerability in the Agno field_type parameter, highlighting its exploitation potential without indicating active attacks or available mitigations.

    0000049
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appagnoagno---

Explore more