Strands Agents Tools: Critical Credential Leak in elasticsearch_memory
Strands Agents' elasticsearch_memory tool (versions < 0.7.0) has a nasty SSRF vulnerability that can leak your Elasticsearch API keys. The LLM can control connection parameters and trick the tool into sending credentials to attacker-controlled servers. If you're running affected versions, update immediately—this one requires action.