top of page
perceptive_background_267k.jpg

agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplyi…

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 21:09:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Web Technologies

Agno version 2.6.5 contains a critical SQL injection vulnerability in its ClickHouse vector database backend. The vulnerability exists in the delete_by_metadata() method where unsafe f-string interpolation in clickhousedb.py allows attackers to inject arbitrary SQL expressions through malicious metadata keys and values. Attackers can exploit this flaw to delete all rows, target specific data, or extract sensitive information using error-based or blind SQL injection techniques. The vulnerability affects the vector database functionality and poses significant risks to data integrity and confidentiality.

Technical details

Mitigation steps:

Affected products:

agno
ClickHouse

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page