CVE-2026-35002
Agno software versions before 2.3.24 allow attackers to run arbitrary Python code by manipulating the field_type parameter in a FunctionCall. This flaw lets a remote attacker execute any code on the affected system without needing to log in or interact with the user.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Agno software, any version earlier than 2.3.24, typically used by organizations that rely on Agno for data modeling and execution.
Real-world impact
An attacker could run malicious code on the target machine, potentially taking full control, exfiltrating data, installing malware, or disrupting services. The impact is broad because the code runs with the privileges of the Agno process.
Why this severity
The CVSS score of 9.3 reflects a remote, unauthenticated, high‑impact vulnerability that allows attackers to execute arbitrary code with the same privileges as the Agno service, without any user interaction.
What to do about it
- 01Upgrade Agno to version 2.3.24 or later.
NVD description
Timeline
- Apr 2, 2026 · Apr 2, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/agno-agi/agno/commit/cbf675…patch
- github.com/agno-agi/agno/releases/tag/…product
- vulncheck.com/advisories/agno-field-type-…third party advisory