โ Back to Database
Memory Replay Attack
๐ HIGH
memory
proven
AVE-2025-0089
ยท aka: Context Injection via History
Summary
Attacker crafts conversation history entries that, when replayed from memory, execute as fresh instructions.
Blast Radius
Historical injections reactivate on memory retrieval.
Prerequisites
Agent with conversation history retrieval.
Environment
- Frameworks: LangGraph, CrewAI
- Models tested: [Available in NAIL SDK]
- Multi-agent: No
- Tools required: No
- Memory required: Yes