Code execution via file_name path traversal
Published Aug 19, 2026 · Updated Aug 20, 2026
Path traversal in PythonTools in Agno through 710d7e7 allows attackers to read, write, or execute files via crafted file_name input. The read_file, save_to_file, and run_python_file actions join untrusted file_name values to base_dir and, before the referenced patch commit 710d7e7, did not verify that the resolved path stayed under that directory. Exposure requires attacker control of a tool invocation or prompt-influenced agent input, and impact is bounded by the Agno process user's filesystem permissions and ability to run Python from attacker-chosen paths.
Summary
What happened
Path traversal in PythonTools in Agno through 710d7e7 allows attackers to read, write, or execute files via crafted file_name input. The read_file, save_to_file, and run_python_file actions join untrusted file_name values to base_dir and, before the referenced patch commit 710d7e7, did not verify that the resolved path stayed under that directory. Exposure requires attacker control of a tool invocation or prompt-influenced agent input, and impact is bounded by the Agno process user's filesystem permissions and ability to run Python from attacker-chosen paths.
The record
- CVE
- CVE-2026-76832
- Published
- Aug 19, 2026
- Updated
- Aug 20, 2026
- Vendor
- Agno
- Product
- Agno
- Classifications
- CWE-22, T1059.006, T1005
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 19, 2026CVE publishedPublication date reported by the CVE source.
- Aug 20, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <=710d7e7
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo