agno-agi agno Model Context Protocol mcp.py MultiMCPTools os command injection

CVE Details

Basic Information

Title agno-agi agno Model Context Protocol mcp.py MultiMCPTools os command injection
Type cve
Published 2025-08-06T17:02:04.987Z
Modified 2025-08-06T17:31:11.272Z

Product Information

Vendor agno-agi
Product agno
Version 1.7.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description This vulnerability allows remote attackers to inject OS commands in the Model Context Protocol Handler of agno-agi’s agno tool, potentially leading to system compromise. The issue exists in versions up to 1.7.5 and was publicly disclosed without a vendor response.
AI Severity Medium
AI Vendor agno-agi
AI Product agno
AI Version 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5

Affected Products

  • agno-agi agno 1.7.0
  • agno-agi agno 1.7.1
  • agno-agi agno 1.7.2
  • agno-agi agno 1.7.3
  • agno-agi agno 1.7.4
  • agno-agi agno 1.7.5

Additional Information

CWE List CWE-78, CWE-77
Source VulDB

Description

A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTools in the library libs/agno/agno/tools/mcp.py of the component Model Context Protocol Handler. The manipulation of the argument command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.