Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agno-agi
Agno-agi agno |
|
| Vendors & Products |
Agno-agi
Agno-agi agno |
|
| Metrics |
ssvc
|
Thu, 02 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Agno field_type Eval Injection Arbitrary Code Execution | Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution |
Thu, 02 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution. | |
| Title | Agno field_type Eval Injection Arbitrary Code Execution | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-02T15:23:20.841Z
Reserved: 2026-03-31T20:40:15.617Z
Link: CVE-2026-35002
Updated: 2026-04-02T15:23:13.911Z
Status : Received
Published: 2026-04-02T15:16:52.063
Modified: 2026-04-02T15:16:52.063
Link: CVE-2026-35002
No data.
OpenCVE Enrichment
Updated: 2026-04-02T20:20:58Z