{"data":{"id":"67b17d83-b9e3-456d-baf6-e71e0fa121bf","title":"CVE-2026-37003: Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh","summary":"Agno versions up to 2.5.8 have a critical vulnerability where PythonTools and ShellTools components don't filter (sanitize) text generated by the LLM before running it as code, allowing attackers to embed malicious instructions in web pages or documents to execute arbitrary code on the server. An unauthenticated attacker can exploit this by tricking the agent into running dangerous commands through prompt injection (hiding malicious instructions in the AI's input).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-37003","publishedAt":"2026-08-27T20:17:41.107Z","cveId":"CVE-2026-37003","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Agno"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-27T20:17:41.107Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}}