External risk intelligence

Agno Prompt Injection RCE via PythonTools and ShellTools

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-37003

The vulnerability exists in agent tools designed to process external content such as web pages or documents. Because these agents are frequently deployed as internet-facing applications or services to interact with public data, the attack surface is commonly reachable from the internet.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in Agno software allows unauthenticated attackers to execute arbitrary code and commands on host servers by embedding malicious instructions within content processed by the agent. The exploitation of prompt injection in PythonTools and ShellTools components could lead to significant compromise of the underlying server infrastructure.

  • Agno software has a critical remote code execution flaw.
  • Attacker can run any command on the server.
  • Confirm if Agno is used and assess potential impact.

Attack Path

How an attacker could exploit the issue

An attacker could initiate an attack by crafting malicious content, such as a web page or document, and directing the Agno agent to process it. Since the agent uses unsanitized input from its language model to execute code, specially designed instructions within this content can trick the agent into running arbitrary commands on the server. This can lead to unauthorized code execution and control over the host system.

  • Attacker embeds instructions in external content.
  • Agent processes unsanitized LLM-generated arguments.
  • Risk of arbitrary code and OS command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code and OS commands on the host server. This could happen when the agent processes untrusted content, such as web pages or documents, that contain specially crafted instructions. The PythonTools and ShellTools components are susceptible because they pass LLM-generated arguments directly to execution functions without proper sanitization.

  • Arbitrary code execution on host.
  • LLM-generated content prompts injection.
  • Server compromise via OS commands.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Agno's PythonTools and ShellTools components could allow unauthenticated attackers to execute arbitrary code by embedding malicious instructions in processed content. The most immediate action is to identify all instances of Agno, confirm their reachability and business criticality, and then determine the accountable owner for remediation.

  • Identify Agno instances and criticality.
  • Confirm exposure and business impact.
  • Plan remediation with accountable owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Agno and what is it used for?

Agno is a framework used to build intelligent agents capable of processing data and performing tasks. It includes specialized components like PythonTools and ShellTools that allow these agents to execute code or run system commands to help complete complex workflows involving web pages, documents, and other external information.

What does CWE-94 mean in the context of CVE-2026-37003?

CWE-94 refers to Improper Control of Generation of Code. In this vulnerability, it means the software fails to properly check or clean instructions generated by an LLM before passing them to system functions. Because these tools treat the LLM output as trusted commands, an attacker can manipulate the process to execute unauthorized code on the underlying server.

How does an attacker trigger this vulnerability?

An attacker triggers the vulnerability by feeding the Agno agent malicious content, such as a crafted document or a web page, containing hidden instructions. This does not trigger if the agent is only processing sanitized or internal data that lacks these adversarial prompts. The flaw is specifically tied to the agent's reliance on unsanitized LLM output during its execution phase.

Is my Agno deployment at risk if it is internal?

Halo Surface Signal notes that while internet-facing agents have a clear path for attackers, any agent configured to process untrusted external content carries risk. Even if your service is internal, if it retrieves and processes public web data or files from untrusted sources, an attacker could potentially reach the vulnerability through those content channels.

What should I do to secure my environment from this flaw?

Start by locating all instances of Agno within your infrastructure to understand where PythonTools and ShellTools are active. Once identified, evaluate whether these agents need to process external, untrusted data. Coordinate with the system owners to prioritize these instances for updates or configuration changes that restrict the tools from executing unsanitized commands.

References