PT-2026-22102 · Agenta+2 · Agenta-Api+2

Jackfromeast

+1

·

Published

2026-02-26

·

Updated

2026-03-19

·

CVE-2026-27952

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Agenta-API versions prior to 0.48.1
Description Agenta is an open-source LLMOps platform. In Agenta-API versions prior to 0.48.1, a Python sandbox escape existed in Agenta's custom code evaluator. The platform used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but incorrectly whitelisted the numpy package as safe within the sandbox. This allowed authenticated users to bypass the sandbox and achieve arbitrary code execution on the API server. The escape path was through numpy.ma.core.inspect, which exposes Python's introspection utilities – including sys.modules – thereby providing access to unfiltered system-level functionality like os.system. The custom code evaluator runs server-side within the API process.
Recommendations Update to version 0.48.1 or later to resolve the issue. Versions 0.60 and later have removed the RestrictedPython sandbox entirely and replaced it with a different execution model.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-27952
GHSA-PMGP-2M3V-34MQ
PYSEC-2026-6

Affected Products

Agenta-Api
Restrictedpython
Numpy