CVE-2026-19111 - Insecure dire... Note

CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools

A critical vulnerability, CVE-2026-19111, has been identified in the Strands Agents SDK, specifically impacting the strands-agents-tools package. This vulnerability affects versions prior to 0.8.3. The issue lies within the mongodb_memory, elasticsearch_memory, and mem0_memory tools. These tools incorrectly use a user-controlled namespace parameter for tenant isolation. A malicious actor can craft a prompt to manipulate this namespace. This manipulation allows unauthorized access to other tenants' stored agent memories. Attackers can read, modify, or delete memories belonging to different users. They can also inject false memories into another tenant's namespace. Furthermore, standalone mongodb_memory and elasticsearch_memory functions expose connection parameters. This could permit redirection of the memory layer to an attacker-controlled cluster. Users are strongly advised to update to a version of strands-agents-tools greater than or equal to 0.8.3.