id: PYSEC-2026-1077 published: "2026-07-07T16:03:09.364557Z" modified: "2026-07-07T17:23:33.341090Z" aliases: - CVE-2025-64168 - GHSA-vw84-hprm-cxmm summary: Agno session state overwrites between different sessions/users details: "### Impact\nUnder certain conditions (under high concurrency), when `session_state` is passed to an Agent or Team during run or arun calls, a race condition can occur, causing a `session_state` to be assigned and persisted to the incorrect session. This may result in user data from one session being exposed to another user.\n\n### Patches\nThis has been patched in version 2.2.2. Upgrade with `pip install -U agno`." affected: - package: name: agno ecosystem: PyPI purl: pkg:pypi/agno ranges: - type: ECOSYSTEM events: - introduced: 2.0.0 - fixed: 2.2.2 versions: - 2.0.0 - 2.0.1 - 2.0.10 - 2.0.11 - 2.0.2 - 2.0.3 - 2.0.4 - 2.0.5 - 2.0.6 - 2.0.7 - 2.0.8 - 2.0.9 - 2.1.0 - 2.1.1 - 2.1.10 - 2.1.2 - 2.1.3 - 2.1.4 - 2.1.5 - 2.1.6 - 2.1.7 - 2.1.8 - 2.1.9 - 2.2.0 - 2.2.1 references: - type: WEB url: https://github.com/agno-agi/agno/security/advisories/GHSA-vw84-hprm-cxmm - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-64168 - type: PACKAGE url: https://github.com/agno-agi/agno - type: PACKAGE url: https://pypi.org/project/agno - type: ADVISORY url: https://github.com/advisories/GHSA-vw84-hprm-cxmm severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N