Skip to main content
EPSS 0.4%top 69%

CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools

0
Medium
VulnerabilityCVE-2026-19111cloudaicvecve-2026-19111cwe-639gcve
Published: 08/20/2026 (08/20/2026, 21:35:57 UTC)
Source: AWS Security Bulletins

Description

Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the mongodb_memory, elasticsearch_memory, and mem0_memory tools for storing and retrieving agent memories. We identified CVE-2026-19111, an insecure direct object reference (IDOR) issue in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. Each tool uses a namespace field as the sole tenant-isolation key, and that namespace was exposed as a parameter the large language model (LLM) could control through the tool schema. A crafted prompt could cause a tool to emit a call with a forged namespace, allowing a remote authenticated user to read, modify, or delete memories belonging to other tenants, or to inject false memories into another tenant's namespace. The standalone mongodb_memory and elasticsearch_memory functions additionally exposed connection parameters, which could allow the memory layer to be redirected to an actor-specified cluster. Impacted versions: < 0.8.3 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Affected software

strands-agents-tools
pkg:npm/strands-agents-tools
Affected versions
<0.8.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 20:55:58 UTC

Technical Analysis

Strands Agents is an open-source SDK for AI agents, with strands-agents-tools providing memory storage tools such as mongodb_memory, elasticsearch_memory, and mem0_memory. CVE-2026-19111 is an IDOR vulnerability where the namespace parameter, used for tenant isolation, is exposed to manipulation by the large language model controlling the tool schema. This flaw enables a remote authenticated user to forge namespaces, thereby reading, modifying, deleting, or injecting memories across tenant boundaries. Moreover, the standalone mongodb_memory and elasticsearch_memory tools expose connection parameters, potentially allowing redirection of memory operations to attacker-specified clusters. The vulnerability affects all versions before 0.8.3. The vendor has released version 0.8.3 to address this issue and recommends upgrading. Workarounds include avoiding deployment of these tools in multi-tenant environments or restricting to single-tenant setups with fixed namespaces and avoiding standalone functions that accept connection parameters.

Potential Impact

A remote authenticated user can exploit this vulnerability to bypass tenant isolation by forging namespaces, leading to unauthorized reading, modification, deletion, or injection of memories belonging to other tenants. This compromises data confidentiality and integrity within multi-tenant AI agent deployments. Additionally, exposure of connection parameters in standalone tools could allow attackers to redirect memory operations to clusters under their control, potentially enabling further unauthorized access or data manipulation.

Mitigation Recommendations

An official fix is available in strands-agents-tools version 0.8.3. It is strongly recommended to upgrade to this version to remediate the vulnerability. Until upgrading, do not deploy the mongodb_memory, elasticsearch_memory, or mem0_memory tools in multi-tenant agent environments where multiple tenants share a single deployment. Restrict these tools to single-tenant deployments with a fixed namespace per request. Avoid using the standalone mongodb_memory or elasticsearch_memory functions that accept connection parameters to prevent redirection attacks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-077-aws/","fetched":true,"fetchedAt":"2026-08-06T18:26:55.862Z","wordCount":277}

Threat ID: 6a74d1efbf8831d539259396

Added to database: 08/06/2026, 18:26:55 UTC

Last enriched: 08/13/2026, 20:55:58 UTC

Last updated: 09/18/2026, 22:01:32 UTC

Views: 94

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses