Impact
AI Agent Automation contains missing ownership checks in its memory APIs for versions prior to 0.9.1. The memory controller authenticates requests but fails to verify that the caller’s agent or memory identifiers belong to the authenticated user. An attacker who is authenticated and knows or obtains another user’s agentId or memory _id can read confidential memory content, delete a single memory entry, or clear all memory of that victim agent. This results in unauthorized disclosure of conversation history, agent context, task data, embeddings, and metadata, and causes data loss. The flaw aligns with CWE‑862 – Restricted Write Access.
Affected Systems
The vulnerability affects the modular AI agent workflow automation platform developed by vmDeshpande, specifically the AI Agent Automation product. All releases earlier than 0.9.1 are impacted; version 0.9.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% reflects a low probability of exploitation at this time. The issue is not yet listed in the CISA KEV catalog. The likely attack vector is an authenticated user who has or can obtain another user’s identifiers; no local or remote code execution is required. Once exploited, the attacker can read or delete sensitive data across tenant boundaries, leading to significant confidentiality and integrity violations. No public exploits are known, but the high impact warrants prompt remediation.
OpenCVE Enrichment