Intel

AIKIDO-2026-10781

agno is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 8, 2026

86

High Risk

This Affects:

PYTHONagno
2.0.0 - 2.6.4
Fixed in 2.6.5
Are you affected? Scan for Free

TL;DR

LLMsTxt-style helpers could retrieve remote text resources based on agent prompts without a tight host allowlist, widening the blast radius for unintended egress during automated browsing of linked endpoints. Redirect handling amplified the risk profile because fetched chains could leave operator-approved origins without explicit operator intent. The mitigation introduces host allowlisting controls and tightens fetch semantics so retrieval stays confined to trusted namespaces.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

agno is vulnerable to Server-Side Request Forgery (SSRF) in versions 2.0.0 - 2.6.4.

How to fix this

Upgrade the agno library to the patch version.