Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.
References
Affected products
- <2.3.24
- ==cbf675521d4d2281925a051784a3b94172e56416
Matching in nixpkgs
pkgs.agnos
Obtains certificates from Let's Encrypt using DNS-01 without the need for API access to the DNS provider
pkgs.iagno
Computer version of the game Reversi, more popularly called Othello
pkgs.nixf-diagnose
CLI wrapper for nixf-tidy with fancy diagnostic output
pkgs.coc-diagnostic
diagnostic-languageserver extension for coc.nvim
-
nixos-unstable 0-unstable-2025-01-15
- nixpkgs-unstable 0-unstable-2025-01-15
- nixos-unstable-small 0-unstable-2025-01-15
pkgs.diagnostic-languageserver
General purpose Language Server that integrate with linter to support diagnostic features
pkgs.vimPlugins.coc-diagnostic
diagnostic-languageserver extension for coc.nvim
-
nixos-unstable 0-unstable-2025-01-15
- nixpkgs-unstable 0-unstable-2025-01-15
- nixos-unstable-small 0-unstable-2025-01-15
pkgs.haskellPackages.castagnoli
Portable CRC-32C
pkgs.python312Packages.django-agnocomplete
front-end agnostic toolbox for autocompletion fields
pkgs.python313Packages.django-agnocomplete
front-end agnostic toolbox for autocompletion fields
pkgs.python314Packages.django-agnocomplete
front-end agnostic toolbox for autocompletion fields
pkgs.home-assistant-component-tests.diagnostics
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-component-tests.diagnostics
Open source home automation that puts local control and privacy first
Package maintainers
-
@justinas Justinas Stankevičius <justinas@justinas.org>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@dasj19 Daniel Șerbănescu <daniel@serbanescu.dk>
-
@hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@LorenzBischof Lorenz Bischof <nix@lorenzbischof.ch>
-
@jcollie Jeffrey C. Ollie <jeff@ocjtech.us>