SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76832

HIGH · CVSS 8.8 EPSS 0.84% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A path traversal vulnerability in Agno's PythonTools allows attackers to manipulate the file_name argument to read, write, or execute arbitrary files on the system. By injecting parent-directory traversal sequences, an attacker can bypass directory restrictions and access sensitive files or execute malicious code with the privileges of the process user. Organizations using Agno's PythonTools should prioritize patching this vulnerability to mitigate the risk of unauthorized file access and code execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76832
Severity
HIGH
CVSS
8.8
EPSS
0.84%

Original NVD Description

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions. Attackers can inject traversal sequences such as '../../../../../../etc/passwd' through direct tool invocation or via prompt injection embedded in agent-processed content to escape the intended base_dir boundary and achieve arbitrary file read, arbitrary file write, or arbitrary Python code execution within the process user's authority.