{"data":{"id":"6c26b474-7a9d-462c-8525-5dfb0e942a1e","title":"CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool","summary":"The http_request tool in Strands Agents (an SDK for building AI agents) has an authorization flaw where an attacker could trick the LLM into routing requests through a malicious proxy server. Even though the tool checks that requests only go to approved hostnames, an attacker using indirect prompt injection (hiding instructions in untrusted web content the agent reads) could bypass this by controlling the proxies parameter, causing sensitive credentials to be sent in cleartext to their server.","solution":"Update strands-agents-tools to version 0.8.2 or later.","labels":["security"],"sourceUrl":"https://aws.amazon.com/security/security-bulletins/rss/2026-069-aws/","publishedAt":"2026-07-31T19:41:06.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Strands Agents","strands-agents-tools"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-31T19:41:06.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}