CVE-2026-76832: Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to re
Summary
Agno's PythonTools has a path traversal vulnerability (a flaw where attackers use sequences like '../../' to access files outside the intended directory) in its file handling functions. Attackers can exploit this by injecting directory-traversal sequences through direct tool use or prompt injection (tricking an AI by hiding instructions in its input) to read, write, or run arbitrary files on the system.
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
network
low
none
required
August 19, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76832
First tracked: August 19, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 92%