SQL Injection Vulnerability in Agno's ClickHouse Vector Database
CVE-2026-10105
8.7HIGH
What is CVE-2026-10105?
Agno version 2.6.5 is vulnerable to SQL injection due to unsafe f-string interpolation in the clickhousedb.py file. Attackers can exploit this vulnerability by providing malicious metadata keys and values to the delete_by_metadata() method, enabling them to execute arbitrary SQL expressions. Successful exploitation may lead to the deletion of all rows, targeting specific data, or extracting information using error-based or blind SQL injection techniques.
Affected Version(s)
agno 0 <= 2.6.5
agno 0 <= 26a7439b803c0ccc9a58ee53572d8088a678923f
agno 0
