CVE-2025-8665 Overview
CVE-2025-8665 is an operating system command injection vulnerability in the agno-agi/agno Python library through version 1.7.5. The flaw resides in the MCPTools and MultiMCPTools functions within libs/agno/agno/tools/mcp.py, part of the Model Context Protocol (MCP) handler. Attackers can manipulate the command argument to inject arbitrary operating system commands. The issue is classified under [CWE-77] Improper Neutralization of Special Elements Used in a Command. Public exploit details have been disclosed, and the vendor did not respond to disclosure attempts.
Critical Impact
Authenticated remote attackers can execute arbitrary operating system commands on hosts running vulnerable agno MCP tool integrations, enabling potential data theft, lateral movement, or AI agent compromise.
Affected Products
- agno-agi agno library versions up to and including 1.7.5
- MCPTools function in libs/agno/agno/tools/mcp.py
- MultiMCPTools function in libs/agno/agno/tools/mcp.py
Discovery Timeline
- 2025-08-06 - CVE-2025-8665 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8665
Vulnerability Analysis
The agno framework provides Python tooling for building AI agents that interact with external systems through the Model Context Protocol. The MCPTools and MultiMCPTools classes in libs/agno/agno/tools/mcp.py accept a command argument used to spawn MCP server processes. The library passes this argument to an operating system shell without sufficient neutralization of shell metacharacters. An attacker who influences the command parameter can append or chain additional commands using shell operators. The vulnerability falls under [CWE-77] Improper Neutralization of Special Elements Used in a Command.
Root Cause
The root cause is unsafe construction of a subprocess invocation from attacker-controllable input. When command values originate from prompts, configuration files, or upstream agent outputs, the library does not validate or escape shell metacharacters before execution. Any component that feeds untrusted content into MCPTools or MultiMCPTools becomes an injection sink.
Attack Vector
Exploitation requires that a caller pass attacker-influenced data into the command parameter of an affected function. In agentic AI deployments this can occur through prompt injection, tainted tool descriptions, or malicious MCP server metadata. Once injected, the crafted command string executes with the privileges of the process hosting the agno agent.
No verified exploit code is published in this dataset. Refer to the GitHub Vulnerability Repository and the GitHub PoC for Vulnerability for the disclosed proof-of-concept details.
Detection Methods for CVE-2025-8665
Indicators of Compromise
- Unexpected child processes spawned by Python interpreters running agno agents, particularly shells such as sh, bash, or cmd.exe.
- Outbound network connections initiated by MCP server subprocesses to unfamiliar destinations shortly after agent invocation.
- Log entries showing MCPTools or MultiMCPTools invocations containing shell metacharacters such as ;, &&, |, or backticks in the command argument.
Detection Strategies
- Audit application logs for calls into libs/agno/agno/tools/mcp.py where the command value is dynamically constructed from prompts, user input, or remote configuration.
- Instrument the Python runtime to record subprocess invocations originating from agno modules and alert on anomalous command strings.
- Correlate agent conversation traces with process creation telemetry to identify prompt-driven command execution.
Monitoring Recommendations
- Ingest endpoint process creation events into a centralized data lake and pivot on parent-child relationships involving Python agno workloads.
- Baseline the expected set of MCP server binaries per environment and alert on any deviation.
- Monitor for privilege escalation attempts, credential access, or reverse-shell patterns emerging from AI agent hosts.
How to Mitigate CVE-2025-8665
Immediate Actions Required
- Inventory all deployments of the agno-agi/agno library and identify versions at or below 1.7.5.
- Restrict MCPTools and MultiMCPTools invocations to hardcoded, developer-controlled command values; never pass prompt-derived or externally sourced strings.
- Run agno agents under least-privileged service accounts and isolate them in sandboxes or containers with restricted filesystem and network access.
Patch Information
At the time of publication, the vendor had not responded to the disclosure and no fixed release is referenced in the advisory. Monitor the agno project repository and the VulDB #319025 Details entry for patch availability. Until a fix is released, treat the affected functions as unsafe when handling untrusted input.
Workarounds
- Wrap calls to MCPTools and MultiMCPTools with a strict allowlist of permitted commands and reject any input containing shell metacharacters.
- Replace shell-style command strings with argument-vector invocations that bypass shell interpretation where the API supports it.
- Deploy egress filtering and mandatory access controls on hosts running agno agents to limit the blast radius of any successful injection.
# Configuration example: locate vulnerable agno installations
pip show agno | grep -i version
grep -R "MCPTools\|MultiMCPTools" /path/to/project --include="*.py"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
