Prompt injection in Amazon Strands Agents Tools python_repl
Improper input neutralization in the python_repl tool of Amazon Strands Agents Tools before 0.8.5 allows remote attackers to execute arbitrary Python code by bypassing consent gates via crafted prompts.
Disclosed 25 August 2026 · Record updated 13 September 2026
Impact
Remote execution of arbitrary Python code on agent hosts with bypass of human consent gates
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-78379
