Report: Update: CVE-2026-35002 - Agno field_type Eval Injection Arbitrary Code Execution

Report: Update: CVE-2026-35002 - Agno field_type Eval Injection Arbitrary Code Execution

CVE ID :CVE-2026-35002 Published : April 2, 2026, 2:34 p.m. | 39 minutes ago Description :Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
April 2, 2026
Affected Product: Python
Impact: code execution