Strands Agents Tools Hit by Memory Access Vulnerability
Strands Agents memory tools (mongodb_memory, elasticsearch_memory, mem0_memory) have a serious IDOR flaw—CVE-2026-19111. Attackers can craft prompts to access, modify, or delete other tenants' memories by exploiting the exposed namespace parameter. Upgrade to version 0.8.3 or later immediately if you're running versions below that.
source: [aws/security-bulletin]