← volver
CVE-2025-64168

Agno session state overwrites between different sessions/users

CVSS 7.1 HIGHEPSS 0.1%CWE-362CWE-668
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.1EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
31 oct 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team during run or arun calls, a race condition can occur, causing a session_state to be assigned and persisted to the incorrect session. This may result in user data from one session being exposed to another user. This has been patched in version 2.2.2.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Productos afectados
agno-agi · agno

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →