Skip to content
agnoGHSA-vw84-hprm-cxmm

Agno session state overwrites between different sessions/users

High7.1CVE-2025-64168 · Published Oct 31, 2025 · updated Jul 7, 2026

### Impact Under certain conditions (under high concurrency), when `session_state` is passed to an Agent or Team during run or arun calls, a race condition can occur, causing a `session_state` to be assigned and persisted to the incorrect session. This may result in user data from one session being exposed to another user. ### Patches This has been patched in version 2.2.2. Upgrade with `pip install -U agno`.

GitHub advisory

Affected versions

PackageAffectedFixed in
agno
PyPI
>= 2.0.0, < 2.2.22.2.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-362, CWE-668
Also known as
CVE-2025-64168, PYSEC-2026-1077

More agno advisories

All agno
Advisory
agno contains a SQL injection vulnerability
High8.3May 29
Agno is vulnerable to Eval Injection
CriticalApr 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.