Memory WeaponizationTier 3critical
Memory Weaponization: Context Cache Poisoning
Poisoning persistent memory and conversation state
Context cache poisoning targets the compressed conversation history that agents maintain, injecting instructions that will be restored in future sessions.
Attack Details
- Attack ID
- APWN-MW-003
- HMA Check
- MEM-006
- Delivery Methods
- html-comment, invisible-span, meta-tag
- CWE
- CWE-94
- OASB Control
- 9.3
- Severity
- critical
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check MEM-006