


Perceptive Security
SOC/SIEM Consultancy

agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplyi…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 21:09:42
Source:
nvd.nist.gov
Database & Storage, Web Technologies
Agno version 2.6.5 contains a critical SQL injection vulnerability in its ClickHouse vector database backend. The vulnerability exists in the delete_by_metadata() method where unsafe f-string interpolation in clickhousedb.py allows attackers to inject arbitrary SQL expressions through malicious metadata keys and values. Attackers can exploit this flaw to delete all rows, target specific data, or extract sensitive information using error-based or blind SQL injection techniques. The vulnerability affects the vector database functionality and poses significant risks to data integrity and confidentiality.
Technical details
Mitigation steps:
Affected products:
agno
ClickHouse
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10105
https://github.com/agno-agi/agno/issues/7866
https://github.com/agno-agi/agno/pull/7883
https://github.com/agno-agi/agno/pull/7883/changes/26a7439b803c0ccc9a58ee53572d8088a678923f
https://github.com/agno-agi/agno/pull/7883/changes/a0ec99305e782e68ba26f5966c53ad50b5f40132
https://www.vulncheck.com/advisories/agno-sql-injection-via-clickhouse-delete-by-metadata
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
