Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team during run or arun calls, a race condition can occur, causing a session_state to be assigned and persisted to the incorrect session. This may result in user data from one session being exposed to another user. This has been patched in version 2.2.2.
History

Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Agno-agi
Agno-agi agno
Vendors & Products Agno-agi
Agno-agi agno

Fri, 31 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Description Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team during run or arun calls, a race condition can occur, causing a session_state to be assigned and persisted to the incorrect session. This may result in user data from one session being exposed to another user. This has been patched in version 2.2.2.
Title Agno session state overwrites between different sessions/users
Weaknesses CWE-362
CWE-668
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-31T14:58:54.447Z

Updated: 2025-10-31T15:39:39.368Z

Reserved: 2025-10-28T21:07:16.438Z

Link: CVE-2025-64168

cve-icon Vulnrichment

Updated: 2025-10-31T15:39:31.870Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-31T15:15:43.377

Modified: 2025-11-04T15:41:31.450

Link: CVE-2025-64168

cve-icon Redhat

No data.