Skip to content
AWSAWS-2026-072

Prompt injection bypasses shell tool consent gate in Strands Agents Tools

UnratedCVE-2026-18733 · Published Aug 3, 2026 · updated Sep 9, 2026

Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733 . The shell tool includes a human consent gate that prompts the operator to approve commands before they run. The tool also exposed a non_interactive parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted content the agent reads (indirect prompt injection), could set non_interactive to true, which bypasses the consent gate and allows arbitrary operating system commands to execute on the agent's host without operator approval. Impacted versions:   Resolution: This issue has been addressed in strands-agents-tools version 0.8.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until you can upgrade, do not make the ...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733 . The shell tool includes a human consent gate that prompts the operator to approve commands before they run. The tool also exposed a non_interactive parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted content the agent reads (indirect prompt injection), could set non_interactive to true, which bypasses the consent gate and allows arbitrary operating system commands to execute on the agent's host without operator approval. Impacted versions:   Resolution: This issue has been addressed in strands-agents-tools version 0.8.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until you can upgrade, do not make the shell tool available to an agent that processes untrusted content, and run any agent that uses the shell tool in an isolated, least-privilege environment so that executed commands are contained. References: CVE-2026-18733 GHSA-mqvc-p852-wf8x Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-072-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733 . The shell tool includes a human consent gate that prompts the operator to approve commands before they run. The tool also exposed a non_interactive parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted content the agent reads (indirect prompt injection), could set non_interactive to true, which bypasses the consent gate and allows arbitrary operating system commands to execute on the agent's host without operator approval. Impacted versions:   Resolution: This issue has been addressed in strands-agents-tools version 0.8.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until you can upgrade, do not make the shell tool available to an agent that processes untrusted content, and run any agent that uses the shell tool in an isolated, least-privilege environment so that executed commands are contained. References: CVE-2026-18733 GHSA-mqvc-p852-wf8x Please email aws-security@amazon.com with any security

Severity from
no source yet

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.