Skip to content

[Question]: WeWork channel lacks memory isolation — users can leak other users' chat history via prompt injection #4845

Description

@linhuang0405

QwenPaw Version

Latest (current main branch)

Description

The WeWork (企业微信) channel currently does not implement complete memory/session isolation between different users. A user can potentially access another user's chat history or conversation context through prompt injection techniques.

This is a security concern because:

  1. Multiple users interacting with the same QwenPaw instance through WeWork may have their conversation contexts leaked to each other
  2. Malicious users can craft prompts to extract conversation history belonging to other users
  3. This violates the fundamental expectation that each user's conversation is isolated and private

Related PR(s): N/A

Security considerations: This is a multi-tenant isolation vulnerability. Any production deployment serving multiple WeWork users is affected.

Component(s) Affected

  • Channels (DingTalk, Feishu, QQ, Discord, iMessage, etc.)
  • Core / Backend (app, agents, config, providers, utils, local_models)

Steps to Reproduce

  1. Deploy QwenPaw with WeWork channel enabled
  2. User A sends a message with sensitive/contextual information
  3. User B sends a prompt injection message designed to extract prior conversation context
  4. User B receives content from User A's conversation

Actual vs Expected

  • Actual: Conversation context/memory may be shared or leakable across different WeWork users
  • Expected: Each WeWork user should have a completely isolated conversation session with no cross-user data leakage

Additional Notes

  • This issue should be treated with higher priority as it involves user data privacy
  • The fix should ensure that session identifiers (user ID, conversation ID, etc.) are properly scoped per WeWork user
  • Memory stores should be keyed by a unique session identifier that cannot be manipulated through user input

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

questionFurther information is requested

Type

No type

Projects

  • Status
    Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions