CVE-2026-19111

Source
https://cve.org/CVERecord?id=CVE-2026-19111
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19111.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19111
Aliases
  • GHSA-mpxq-953j-42m4
Published
2026-08-06T18:03:21.891Z
Modified
2026-08-08T03:48:18.265229343Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Insecure direct object reference in Strands Agents Tools memory tool namespace isolation
Details

Insecure direct object reference in the mongodbmemory, elasticsearchmemory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter.

To remediate this issue, users should upgrade to version 0.8.3.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19111.json",
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-639"
    ]
}
References

Affected packages

Git / github.com/strands-agents/tools

Affected ranges

Type
GIT
Repo
https://github.com/strands-agents/tools
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.8.3"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9
v0.2.0
v0.2.1
v0.2.10
v0.2.11
v0.2.12
v0.2.13
v0.2.14
v0.2.15
v0.2.16
v0.2.17
v0.2.18
v0.2.19
v0.2.2
v0.2.20
v0.2.21
v0.2.22
v0.2.23
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.2.9
v0.3.0
v0.4.0
v0.4.1
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.6.0
v0.7.0
v0.8.0
v0.8.1
v0.8.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19111.json"