CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool
Summary
A security flaw (CVE-2026-78379) in Strands Agents Tools, a Python SDK for building AI agents, allows attackers to bypass the approval prompt in the python_repl tool (which normally requires human consent before running Python code on a system). An attacker can craft a malicious prompt that uses the batch tool to sneak in a keyword argument, letting them execute arbitrary Python code without permission.
Solution / Mitigation
Update to strands-agents-tools version 0.8.5 or later. The bulletin states the vulnerability exists in 'versions before 0.8.5'.
Classification
Affected Vendors
Related Issues
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-089-aws/
First tracked: August 25, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 92%