CVE-2026-35002 is a critical arbitrary code execution vulnerability affecting Agno versions prior to 2.3.24. Attackers can exploit a flaw in the model execution component by manipulating the field_type parameter to execute arbitrary Python code, leading to remote code execution. Rated with a CVSS score of 9.3 (CRITICAL), this vulnerability allows unauthenticated, remote attackers to achieve full system compromise with low attack complexity and no user interaction. While not currently listed in the KEV catalog and lacking public exploit code on major platforms, it has received some community discussion and is designated as "Active" on the Hot List, indicating its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.24CPE matchmatch criteria | cpe:2.3:a:agno:agno:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.