AWS Latest Bulletins
Follow
CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package offers pre-built tools, including a shell tool for executing OS commands. This shell tool featured a human consent gate for command approval. However, it also exposed a non_interactive parameter controllable by the LLM. A crafted prompt could set this parameter to true, circumventing the consent gate. This bypass allows arbitrary OS commands to run on the agent's host without operator approval. The vulnerability is identified as CVE-2026-18733. Versions prior to 0.8.0 are impacted by this issue. This bulletin requires operator attention. Further updated information is available in the referenced article.