PT-2026-81489 · Amazon · Strands-Agents-Tools
CVE-2026-78379
·
Published
2026-08-25
·
Updated
2026-08-28
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon Strands Agents Tools versions prior to 0.8.5
Description
Improper neutralization of input used for Large Language Model (LLM) prompting in the
python repl tool allows remote actors to execute arbitrary Python code on the agent's host. This occurs by bypassing the human consent gate using a crafted prompt that forwards non interactive mode as a keyword argument through the batch tool. The issue stems from approval flags being accepted from the model rather than exclusively from the operator.Recommendations
Upgrade to version 0.8.5 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Strands-Agents-Tools