Insecure Direct Object Reference in Amazon Strands Agents Tools
CVE-2026-19111
8.6HIGH
What is CVE-2026-19111?
The Amazon Strands Agents Tools contain an insecure direct object reference vulnerability that affects the mongodb_memory, elasticsearch_memory, and mem0_memory functionalities. This issue allows remote authenticated users to manipulate the LLM into making tool calls with a forged namespace parameter, potentially granting access to, or even allowing modifications and deletions of, memories that belong to other tenants. It is crucial for users to upgrade to version 0.8.3 to mitigate this risk.
Affected Version(s)
strands-agents-tools 0 < 0.8.3
