Multiple vulnerabilities in Amazon Strands Agents Tools
Two vulnerabilities were disclosed in Amazon Strands Agents Tools: a prompt injection flaw in the shell tool allowing arbitrary OS command execution, and an insecure direct object reference in memory tools allowing unauthorized access to other tenants' data.
Disclosed 3 August 2026 · Record updated 13 September 2026
Impact
Remote actors could execute arbitrary OS commands; authenticated users could access, modify, or delete memories of other tenants.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18733
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19111
