CVE-2026-18733: Aws Strands-Agents-Tools
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0.
Affected products
- Aws Strands-Agents-Tools: before 0.8.0 (fixed in 0.8.0)
Published 2026-08-03. Last modified 2026-08-04.