CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
Summary
The http_request tool in Strands Agents (an SDK for building AI agents) has an authorization flaw where an attacker could trick the LLM into routing requests through a malicious proxy server. Even though the tool checks that requests only go to approved hostnames, an attacker using indirect prompt injection (hiding instructions in untrusted web content the agent reads) could bypass this by controlling the proxies parameter, causing sensitive credentials to be sent in cleartext to their server.
Solution / Mitigation
Update strands-agents-tools to version 0.8.2 or later.
Classification
Affected Vendors
Related Issues
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-069-aws/
First tracked: July 31, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 92%