CVE Database
/

CVE-2026-10105

Back to search

CVE-2026-10105

Published: May 29, 2026

Modified: Jun 2, 2026

PUBLISHED

CVSS v3.1

8.3

HIGH

Description

agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete all rows, target specific rows, or extract information through error-based or blind SQL injection techniques.

VendorProductVersions

agno-agi

agno

affected
0 - <= 2.6.5
affected
0 - <= 26a7439b803c0ccc9a58ee53572d8088a678923f
affected
0 - <= a0ec99305e782e68ba26f5966c53ad50b5f40132

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now