{"id":"CVE-2026-76832","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-76832","summary":"Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory…","details":"Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions. Attackers can inject traversal sequences such as '../../../../../../etc/passwd' through direct tool invocation or via prompt injection embedded in agent-processed content to escape the intended base_dir boundary and achieve arbitrary file read, arbitrary file write, or arbitrary Python code execution within the process user's authority.","published":"2026-08-19T22:17:27.960","modified":"2026-08-19T22:17:27.960","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/agno-agi/agno/commit/710d7e7f846f93b7a3eadfd3e77075428c39e803","label":"agno-agi/agno@710d7e7"},"references":[{"type":"WEB","url":"https://github.com/agno-agi/agno"},{"type":"WEB","url":"https://github.com/agno-agi/agno/commit/710d7e7f846f93b7a3eadfd3e77075428c39e803"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/agno-pythontools-path-traversal-via-joinpath-file-name-argument"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T22:17:27.960"}}