AE-63NJWB38
Per-user agent entity memory shares one row across users with the same entity name, leaking private facts and losing data
IDENTITY FAILUREseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: LOW
EntityMemoryStore with namespace="user" built the row key without a user component while reads filtered by user_id, and the upsert never rewrote user_id. When two users recorded an entity with the same name and type, the second user's facts overwrote the first user's row, leaked into the first user's reads and agent prompt context, and the second user could never read their own data. The merged fix embeds a user digest in the key and re-keys existing rows in the v3.0.0 migration.
- Framework / agent
- Agno · agno agent with learning/entity memory in multi-user AgentOS deployment
- Remediation attempts
- TESTEDSUGGESTEDSUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- GITHUB ISSUE Entity memory namespace="user" does not isolate users: row key has no user component, so same-named entities collide across users (data loss + cross-user leak) — github.com/agno-agi/agno, retrieved 2026-09-29
- GITHUB PULL REQUEST fix: isolate entity memory rows per user under namespace="user" — github.com/agno-agi/agno, retrieved 2026-09-29
- GITHUB PULL REQUEST [fix] Key entity memory per user under the "user" namespace (#9319) — github.com/agno-agi/agno, retrieved 2026-09-29
Symptoms
- One user's reads return another user's private entity fact while the other user's read returns nothing
- Both writes report success with no error or warning
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-63NJWB38. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.