CVE-2026-10105 | agno-agi agno up to 2.6.5 ClickHouse Vector Database Backend clickhousedb.py delete_by_metadata sql injection (Issue 7866)
A vulnerability, which was classified as critical, was found in agno-agi agno up to 2.6.5. Impacted is the function delete_by_metadata of the file clickhousedb.py of the component ClickHouse Vector Database Backend. Executing a manipulation can lead to sql injection.
This vulnerability is handled as CVE-2026-10105. The attack can be executed remotely. There is not any exploit available.
A patch should be applied to remediate this issue.