Prompt injection bypasses shell tool consent gate in Strands Agents Tools
UnratedCVE-2026-18733 · Published Aug 3, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733 . The shell tool includes a human consent gate that prompts the operator to approve commands before they run. The tool also exposed a non_interactive parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted content the agent reads (indirect prompt injection), could set non_interactive to true, which bypasses the consent gate and allows arbitrary operating system commands to execute on the agent's host without operator approval. Impacted versions: Resolution: This issue has been addressed in strands-agents-tools version 0.8.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until you can upgrade, do not make the ...
Affected versions
Details and references
Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733 . The shell tool includes a human consent gate that prompts the operator to approve commands before they run. The tool also exposed a non_interactive parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted content the agent reads (indirect prompt injection), could set non_interactive to true, which bypasses the consent gate and allows arbitrary operating system commands to execute on the agent's host without operator approval. Impacted versions: Resolution: This issue has been addressed in strands-agents-tools version 0.8.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until you can upgrade, do not make the shell tool available to an agent that processes untrusted content, and run any agent that uses the shell tool in an isolated, least-privilege environment so that executed commands are contained. References: CVE-2026-18733 GHSA-mqvc-p852-wf8x Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-072-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733 . The shell tool includes a human consent gate that prompts the operator to approve commands before they run. The tool also exposed a non_interactive parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted content the agent reads (indirect prompt injection), could set non_interactive to true, which bypasses the consent gate and allows arbitrary operating system commands to execute on the agent's host without operator approval. Impacted versions: Resolution: This issue has been addressed in strands-agents-tools version 0.8.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until you can upgrade, do not make the shell tool available to an agent that processes untrusted content, and run any agent that uses the shell tool in an isolated, least-privilege environment so that executed commands are contained. References: CVE-2026-18733 GHSA-mqvc-p852-wf8x Please email aws-security@amazon.com with any security
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB... | Unrated | No fix yet |
| Aug 5 | Improper limitation of a pathname in AWS Transform MCP Server | Unrated | No fix yet |
| Aug 4 | AWS: code execution | Unrated | No fix yet |
| Aug 4 | Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation | Unrated | No fix yet |
| Aug 3 | Disabled SSH host key verification in AWS CLI EMR helper commands | Unrated | No fix yet |
| Aug 3 | Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt... | Unrated | No fix yet |