Agentatech maintains a focused vulnerability footprint centered on its Agenta platform, with the recurring signal rooted in template-engine and code-generation components vulnerable to injection attacks. These weakness classes—code injection and improper neutralization of template-engine elements—reflect the dynamic code handling inherent to agent and automation platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agentatech over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27952CRITICAL Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used Restri | Feb 26, 2026 | 9.9 | 34 | NO | NO |
CVE-2026-27961HIGH Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template renderi | Feb 26, 2026 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agentatech.
Media articles that mention a CVE ID that affects a product developed by Agentatech — matched by CVE ID, not by vendor name.