Vulnerability Description
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument through the batch tool. To remediate this issue, users should upgrade to version 0.8.5 or later.
CVSS Score
HIGH
References
- https://aws.amazon.com/security/security-bulletins/2026-089-aws/
- https://pypi.org/project/strands-agents-tools/0.8.5/
FAQ
What is CVE-2026-78379?
CVE-2026-78379 is a vulnerability with a CVSS score of 8.1 (HIGH). Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's ho...
How severe is CVE-2026-78379?
CVE-2026-78379 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-78379?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.