CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
Summary
Strands Agents Tools, an open-source SDK for building AI agents, has a vulnerability where the shell tool (which runs operating system commands) can be tricked by prompt injection (hiding malicious instructions in text the AI reads) to bypass its human approval requirement. An attacker could craft input that sets a hidden parameter to true, allowing commands to execute on the system without the operator's permission.
Classification
Affected Vendors
Related Issues
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-072-aws/
First tracked: August 3, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%