bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-78379

show all
Tuesday, August 25, 2026

Strands Agents Tools python_repl: Consent Bypass Vulnerability Patched

Amazon Strands Agents Tools versions before 0.8.5 contain CVE-2026-78379, a consent bypass flaw in the python_repl tool that lets attackers execute arbitrary Python code on your host by sneaking non_interactive_mode through the batch tool. The vulnerability bypasses the human approval gate that normally protects code execution. Action required: upgrade to version 0.8.5 or later immediately if you're running affected versions.

source: [aws/security-bulletin]