MEDIUM SEVERITYCONFIRMED

InMemorySessionService silently overwrites existing session via whitespace-padded ID

Package
google-adk
Version
1.28.0
Verified
2026-03-28

Description

In `google.adk.sessions.in_memory_session_service.InMemorySessionService._create_session_impl`, the duplicate check queries with the raw (unstripped) session ID while the storage step strips whitespace first. Passing `' myid '` bypasses the `AlreadyExistsError` guard for the existing session `'myid'` and silently overwrites its state and event history.

Reproduction

import asyncio
from google.adk.sessions.in_memory_session_service import InMemorySessionService
async def repro():
    svc = InMemorySessionService()
    await svc.create_session(app_name='app', user_id='u1', session_id='myid', state={'owner': 'alice'})
    await svc.create_session(app_name='app', user_id='u1', session_id='  myid  ', state={'owner': 'attacker'})
    s = await svc.get_session(app_name='app', user_id='u1', session_id='myid')
    print(s.state)  # {'owner': 'attacker'} — overwritten
asyncio.run(repro())
← All bugsScan your code →