agno is vulnerable to Authorization Bypass Through User-Controlled Key
88
High Risk
AgentOS MCP tool dispatch could honor caller-supplied tenancy cues instead of anchoring identity to the authenticated JWT subject, letting one authenticated workspace reach memory or tool flows stamped for another user when identifiers drifted across layers. The correction resolves user_id centrally from the verified token subject before executing MCP handlers and aligns downstream memory identity filters so cross-tenant reads and writes cannot piggyback on mismatched IDs.
You are affected if you are using a version that falls within the vulnerable range.
agno is vulnerable to Authorization Bypass Through User-Controlled Key in versions 2.0.0 - 2.6.4.
Upgrade the agno library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant