


Perceptive Security
SOC/SIEM Consultancy

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system c…
Published:
3 augustus 2026 om 00:00:00
Alert date:
4 augustus 2026 om 00:01:37
Source:
nvd.nist.gov
Emerging Technologies, Cloud & Virtualization, Zero-Day Vulnerabilities
A prompt injection vulnerability (CVE-2026-18733) has been identified in the shell tool of Amazon Strands Agents Tools versions prior to 0.8.0. The flaw allows remote actors to execute arbitrary operating system commands on the agent's host machine. Exploitation is achieved via a crafted prompt that sets the non_interactive parameter to true, effectively bypassing the human consent gate designed to prevent unauthorized actions. This type of attack vector is particularly concerning in AI agent frameworks where tool use can have direct system-level consequences. The vulnerability is classified as high severity due to its potential for arbitrary OS command execution. Amazon has released version 0.8.0 of Strands Agents Tools to address this issue. Users are strongly advised to upgrade immediately to mitigate the risk. The issue has been documented in an AWS security bulletin and a GitHub security advisory.
Technical details
Mitigation steps:
Affected products:
Amazon Strands Agents Tools
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18733
https://aws.amazon.com/security/security-bulletins/2026-072-aws/
https://github.com/strands-agents/tools/security/advisories/GHSA-mqvc-p852-wf8x
https://pypi.org/project/strands-agents-tools/0.8.0/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
