
CVE-2026-76832: Agno PythonTools joined file_name onto base_dir with no containment check. A tool call or prompt injection can read, write, or run files as the process user. Upgrade: pip install --upgrade agno (2.3.24+) Do not set restrict_to_base_dir=False. https://hol.org/blog/cve-2026-76832-agno-pythontools-path-traversal
Post summary
The post highlights a path‑traversal bug in Agno PythonTools, supplies a patch via pip upgrade, and warns against a vulnerable configuration.
