top of page
perceptive_background_267k.jpg

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system c…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 22:01:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Emerging Technologies, Cloud & Virtualization, Zero-Day Vulnerabilities

A prompt injection vulnerability (CVE-2026-18733) has been identified in the shell tool of Amazon Strands Agents Tools versions prior to 0.8.0. The flaw allows remote actors to execute arbitrary operating system commands on the agent's host machine. Exploitation is achieved via a crafted prompt that sets the non_interactive parameter to true, effectively bypassing the human consent gate designed to prevent unauthorized actions. This type of attack vector is particularly concerning in AI agent frameworks where tool use can have direct system-level consequences. The vulnerability is classified as high severity due to its potential for arbitrary OS command execution. Amazon has released version 0.8.0 of Strands Agents Tools to address this issue. Users are strongly advised to upgrade immediately to mitigate the risk. The issue has been documented in an AWS security bulletin and a GitHub security advisory.

Technical details

Mitigation steps:

Affected products:

Amazon Strands Agents Tools

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page