top of page
perceptive_background_267k.jpg

agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplyi…

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 21:09:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Web Technologies

Agno version 2.6.5 contains a critical SQL injection vulnerability in its ClickHouse vector database backend. The vulnerability exists in the delete_by_metadata() method where unsafe f-string interpolation in clickhousedb.py allows attackers to inject arbitrary SQL expressions through malicious metadata keys and values. Attackers can exploit this flaw to delete all rows, target specific data, or extract sensitive information using error-based or blind SQL injection techniques. The vulnerability affects the vector database functionality and poses significant risks to data integrity and confidentiality.

Technical details

Mitigation steps:

Affected products:

agno
ClickHouse

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page