PT-2025-44638 · Agno · Agno

Published

2025-10-31

·

Updated

2025-11-04

·

CVE-2025-64168

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Agno versions 2.0.0 through 2.2.1
Description Agno is a multi-agent framework, runtime, and control plane. Under high concurrency, a race condition can occur when session state is passed to Agent or Team during run or arun calls. This can lead to a session state being assigned and persisted to the incorrect session, potentially exposing user data from one session to another user.
Recommendations Update to version 2.2.2 or later.

Exploit

Fix

Race Condition

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64168
GHSA-VW84-HPRM-CXMM

Affected Products

Agno