VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-18733

CVE-2026-18733: A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors

Published Aug 3, 2026 CVSS 7.5

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate.

To remediate this issue, users should upgrade to version 0.8.0.

Affected AI Products

prompt injection
Get the weekly digest. Every Monday: top AI security stories of the week. Free.