MEDIUM SEVERITYCONFIRMED
InMemorySessionService silently overwrites existing session via whitespace-padded ID
Package
google-adk
Version
1.28.0
Verified
2026-03-28
Description
In `google.adk.sessions.in_memory_session_service.InMemorySessionService._create_session_impl`, the duplicate check queries with the raw (unstripped) session ID while the storage step strips whitespace first. Passing `' myid '` bypasses the `AlreadyExistsError` guard for the existing session `'myid'` and silently overwrites its state and event history.
Reproduction
import asyncio
from google.adk.sessions.in_memory_session_service import InMemorySessionService
async def repro():
svc = InMemorySessionService()
await svc.create_session(app_name='app', user_id='u1', session_id='myid', state={'owner': 'alice'})
await svc.create_session(app_name='app', user_id='u1', session_id=' myid ', state={'owner': 'attacker'})
s = await svc.get_session(app_name='app', user_id='u1', session_id='myid')
print(s.state) # {'owner': 'attacker'} — overwritten
asyncio.run(repro())