Executive brief
Agno's PythonTools component allows developers to build AI agents that can read, write, and execute Python files on a system. A path traversal flaw in this component permits attackers to bypass directory restrictions and access arbitrary files on the server, potentially reading sensitive configuration or source code, modifying application files, or executing malicious code with the permissions of the application process.
Technical details
The vulnerability is a classic path traversal flaw in the PythonTools file handling functions (read_file, save_to_file, run_python_file) located in libs/agno/agno/tools/python.py. The root cause is insufficient validation of user-supplied file_name arguments; attackers can inject sequences like '../../../../../../etc/passwd' to escape the intended base_dir boundary. The flaw can be exploited directly via tool invocation or indirectly through prompt injection in agent-processed content. An unauthenticated attacker with network access can read arbitrary files, write files outside the restricted directory, or execute arbitrary Python code within the process's user authority. A fix adding a restrict_to_base_dir parameter was implemented in commit 710d7e7 (2026-01-07).
Affected products
- Agno PythonTools prior to 2026-01-07
Timeline
- 2026-08-19: disclosed: CVE-2026-76832 published
- 2026-01-07: patched: Fix implemented in commit 710d7e7 adding restrict_to_base_dir parameter