---
title: "Memory poisoning"
description: "An injection that writes to an agent's long-term memory, a retrieval corpus, a vector store or a hosted memory service, and so taints every later session that reads from that store."
canonical: https://aigovernanceengineer.com/glossary/memory-poisoning
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Memory poisoning

An injection that writes to an agent's long-term memory, a retrieval corpus, a vector store or a hosted memory service, and so taints every later session that reads from that store [1]. OWASP's agentic list has it as ASI06 Memory & Context Poisoning [2] and MITRE ATLAS as AI Agent Context Poisoning (AML.T0080) [3].

- Developed in: [ch. 23, Memory and context governance](https://aigovernanceengineer.com/bok/governing-agents#memory-and-context-governance)
- Chapters: [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- Contrast with: [Prompt injection](https://aigovernanceengineer.com/glossary/prompt-injection)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-memory-poisoning

## Sources

[1] OWASP GenAI LLM Top 10 2026 (published 3 Aug 2026; LLM01:2026 Prompt Injection, incl. memory persistence; LLM08:2026 Hidden Context Exposure, which replaced System Prompt Leakage: assume hidden context is discoverable, no credentials in it, not a security boundary; final text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
[2] Top 10 for Agentic Applications 2026 (ASI01 Agent Goal Hijack; ASI02 Tool Misuse and Exploitation; ASI03 Identity and Privilege Abuse; ASI04 Agentic Supply Chain Vulnerabilities; ASI05 Unexpected Code Execution (RCE); ASI06 Memory & Context Poisoning; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI09 Human-Agent Trust Exploitation; ASI10 Rogue Agents; Least-Agency; per-tool least-privilege profiles; tool poisoning of a legitimate tool's interface under ASI02, a tool compromised at the source under ASI04). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
[3] MITRE ATLAS data, release v2026.09 (AML.T0080 AI Agent Context Poisoning, .000 Memory; AML.T0110 AI Agent Tool Poisoning). MITRE. 2026-09-15. https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09 (verified: primary)
