{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/agno/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-76832"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PythonTools"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Agno"],"content_html":"\u003cp\u003eAgno's PythonTools component, specifically located in libs/agno/agno/tools/python.py, contains a critical path traversal vulnerability (CVE-2026-76832). This vulnerability stems from improper validation of the file_name argument passed to the tool's core functions: read_file, save_to_file, and run_python_file.\u003c/p\u003e\n\u003cp\u003eAn attacker can bypass intended directory restrictions by providing parent-directory traversal sequences (e.g., ../../../) within the file_name parameter. This can be exploited through direct invocation of these tools or via prompt injection attacks where an agent processes malicious input containing the traversal payloads. Successful exploitation permits an attacker to escape the base_dir boundary, enabling arbitrary file read access, overwriting sensitive system files, or executing arbitrary Python code with the privileges of the application process. This vulnerability presents a high risk for environments where Agno agents are configured to interface with local filesystems or have broad execution authority.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized actors to compromise the integrity and confidentiality of the host environment. By leveraging the save_to_file or run_python_file actions, an attacker can achieve remote code execution (RCE) in the context of the agent process, potentially leading to full system compromise, exfiltration of environment variables or credentials, and persistence within the affected host or container environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Agno library to the patched version that implements strict path normalization and boundary validation for the file_name argument.\u003c/li\u003e\n\u003cli\u003eImplement restrictive filesystem permissions for the service user account running Agno agents to limit the impact of potential traversal attempts.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for suspicious tool input patterns containing repeated directory traversal sequences like \u0026quot;../\u0026quot;.\u003c/li\u003e\n\u003cli\u003eRestrict agent access to unnecessary filesystem paths via environment isolation, such as containerization or chroot jails, where feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T22:45:25Z","date_published":"2026-08-19T22:45:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-agno-python-traversal/","summary":"Agno PythonTools contains a path traversal vulnerability in its read_file, save_to_file, and run_python_file functions that allows attackers to read, write, or execute arbitrary files.","title":"Path Traversal Vulnerability in Agno PythonTools","url":"https://feed.craftedsignal.io/briefs/2026-08-agno-python-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Agno","version":"https://jsonfeed.org/version/1.1"}