Fetching from the wire…
Security2026-08-28 · source-backed
Versions through 2.5.8 pass unsanitized LLM-generated arguments straight to exec(), runpy.run_path() and subprocess.run() (NVD). This is Agno's second disclosure this month after CVE-2026-76832, a PythonTools path traversal via file_name, which points at the tool layer as a whole rather than any single call site.
Each link below shares sources, entities, or timing with this story.
LLM uses OpenAI / Shared entities / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover CVE, RCE; earlier CVE coverage from 2026-08-11.
Linked by a graph relationship (LLM uses OpenAI); both cover CVE, RCE; earlier CVE coverage from 2026-08-08.
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-08-16.
Agno supports MCP / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Agno supports MCP); both cover LLM; earlier LLM coverage from 2026-07-27.
Agno supports MCP / Shared entity: CVE / Earlier coverage / Tension
Linked by a graph relationship (Agno supports MCP); both cover CVE; earlier CVE coverage from 2026-07-23.
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-18.
Agno supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Agno supports MCP); both cover CVE, NVD; reported by the same outlet (nvd.nist.gov).