bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: Strands Agents Tools

show all
Monday, August 3, 2026

Strands Agents Tools: Prompt Injection Bypasses Shell Command Approval

Strands Agents Tools versions below 0.8.0 have a critical vulnerability (CVE-2026-18733) where prompt injection can bypass the shell tool's consent gate. An attacker can craft prompts—like those hidden in untrusted content—to set the non_interactive parameter to true, letting arbitrary OS commands execute without operator approval. Update to version 0.8.0 or later immediately if you're running affected versions.

> source: aws.amazon.com