agno is vulnerable to Authorization Bypass
59
Medium Risk
MCP tool entrypoints accept a call-time tool_name argument, and a model-supplied value can redirect execution to a different tool than the one that was allow-listed, logged, and gated. Because allow-list checks, confirmation prompts, human-in-the-loop approval, and audit logging are keyed to the declared tool, a substituted name lets a different tool run without those controls. This bypasses the intended authorization and approval gates for tool execution. The fix closes over the declared tool.name so the executed tool can no longer be overridden at call time.
You are affected if you are using a version that falls within the vulnerable range and you use MCP tools whose execution is gated by allow-lists, confirmation, or human-in-the-loop approval where model-influenced input can supply a tool name.
agno is vulnerable to Authorization Bypass in versions 1.1.9 - 2.8.7.
Upgrade the agno library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant