CVE-2026-37003: Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh
Summary
Agno versions up to 2.5.8 have a critical vulnerability where PythonTools and ShellTools components don't filter (sanitize) text generated by the LLM before running it as code, allowing attackers to embed malicious instructions in web pages or documents to execute arbitrary code on the server. An unauthenticated attacker can exploit this by tricking the agent into running dangerous commands through prompt injection (hiding malicious instructions in the AI's input).
Vulnerability Details
EPSS: 0.0%
August 27, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-37003
First tracked: August 27, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 95%