You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Question]: WeWork channel lacks memory isolation — users can leak other users' chat history via prompt injection #4845
The WeWork (企业微信) channel currently does not implement complete memory/session isolation between different users. A user can potentially access another user's chat history or conversation context through prompt injection techniques.
This is a security concern because:
Multiple users interacting with the same QwenPaw instance through WeWork may have their conversation contexts leaked to each other
Malicious users can craft prompts to extract conversation history belonging to other users
This violates the fundamental expectation that each user's conversation is isolated and private
Related PR(s): N/A
Security considerations: This is a multi-tenant isolation vulnerability. Any production deployment serving multiple WeWork users is affected.
QwenPaw Version
Latest (current main branch)
Description
The WeWork (企业微信) channel currently does not implement complete memory/session isolation between different users. A user can potentially access another user's chat history or conversation context through prompt injection techniques.
This is a security concern because:
Related PR(s): N/A
Security considerations: This is a multi-tenant isolation vulnerability. Any production deployment serving multiple WeWork users is affected.
Component(s) Affected
Steps to Reproduce
Actual vs Expected
Additional Notes