Impact
The vulnerability is an insecure direct object reference that allows a remote authenticated user to manipulate the namespace field sent to the memory tools (mongodb_memory, elasticsearch_memory, mem0_memory) in Amazon Strands Agents Tools. By forcing the tool to emit calls with a forged namespace, the attacker can read, modify, or delete memories stored for other tenants. This results in a confidentiality breach and denial of data integrity for the affected tenants.
Affected Systems
AWS Strands Agents Tools prior to version 0.8.3; any deployment that uses the memory tools without the 0.8.3 patch is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 reflects a high severity scenario where an authenticated user can impact data of other tenants. The EPSS score is not available, but the KEV catalog does not list the vulnerability, suggesting no widespread exploitation has been observed yet. Exploitation requires the attacker to be authenticated to use the tools and to influence the LLM to generate a tool call with a forged namespace; assuming access to that capability, the attack path is straightforward and does not require database credentials.
OpenCVE Enrichment