agno is vulnerable to Information Disclosure
53
Medium Risk
Tool-result caching builds its cache key from the tool name and call arguments without including the run-context user or session identity. When caching is enabled, a cached result produced for one user or session can be returned to another user issuing the same tool call. This discloses one user's tool results to another across trust boundaries. The fix incorporates user_id and session_id into the cache key so cached results are isolated per identity.
You are affected if you are using a version that falls within the vulnerable range and you enable tool-result caching (cache_results) for tools that use run context across multiple users or sessions.
agno is vulnerable to Information Disclosure in versions 1.2.7 - 2.8.7.
Upgrade the agno library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant