Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument through the batch tool. To remediate this issue, users should upgrade to version 0.8.5 or later. | |
| Title | Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools | |
| First Time appeared |
Amazon
Amazon strands-agents-tools |
|
| Weaknesses | CWE-1427 | |
| CPEs | cpe:2.3:a:amazon:strands-agents-tools:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon strands-agents-tools |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-08-25T19:20:51.512Z
Reserved: 2026-08-24T13:19:59.568Z
Link: CVE-2026-78379
Updated: 2026-08-25T19:20:41.166Z
Status : Received
Published: 2026-08-25T19:16:54.467
Modified: 2026-08-25T20:17:07.817
Link: CVE-2026-78379
No data.
OpenCVE Enrichment
No data.
-
CWE-1427
Improper Neutralization of Input Used for LLM Prompting