To remediate this issue, users should upgrade to version 0.8.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 03 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aws strands Agents Tools
|
|
| Vendors & Products |
Aws strands Agents Tools
|
Mon, 03 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0. | |
| Title | Prompt injection bypasses shell tool consent gate in Strands Agents Tools | |
| First Time appeared |
Aws
Aws strands-agents-tools |
|
| Weaknesses | CWE-1427 | |
| CPEs | cpe:2.3:a:aws:strands-agents-tools:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws strands-agents-tools |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-03T20:35:23.023Z
Reserved: 2026-08-03T18:48:48.218Z
Link: CVE-2026-18733
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T21:30:04Z