Aws Strands Agents Tools
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Aws Strands Agents Tools.
By the Year
In 2026 there have been 3 vulnerabilities in Aws Strands Agents Tools with an average score of 8.1 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3 | 8.10 |
It may take a day or so for new Strands Agents Tools vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Aws Strands Agents Tools Security Vulnerabilities
Insecure DOOR in Amazon Strands Agent Tools <0.8.3 (memory tools)
CVE-2026-19111
8.1 - High
- August 06, 2026
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter. To remediate this issue, users should upgrade to version 0.8.3.
Insecure Direct Object Reference / IDOR
Prompt Injection in Amazon Strands Agents Tools <0.8.0 Allows Remote OS Cmd Exec
CVE-2026-18733
8.8 - High
- August 03, 2026
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0.
1427
Strands Agents Tools 0.8.2: http_request tool Insecure Authorization
CVE-2026-18394
7.4 - High
- July 31, 2026
Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2.
AuthZ
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Aws Strands Agents Tools or by Aws? Click the Watch button to subscribe.