PT-2026-81489 · Amazon · Strands-Agents-Tools

CVE-2026-78379

·

Published

2026-08-25

·

Updated

2026-08-28

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amazon Strands Agents Tools versions prior to 0.8.5
Description Improper neutralization of input used for Large Language Model (LLM) prompting in the python repl tool allows remote actors to execute arbitrary Python code on the agent's host. This occurs by bypassing the human consent gate using a crafted prompt that forwards non interactive mode as a keyword argument through the batch tool. The issue stems from approval flags being accepted from the model rather than exclusively from the operator.
Recommendations Upgrade to version 0.8.5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78379

Affected Products

Strands-Agents-Tools