Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Prompt injection in Amazon Strands Agents Tools python_repl

Improper input neutralization in the python_repl tool of Amazon Strands Agents Tools before 0.8.5 allows remote attackers to execute arbitrary Python code by bypassing consent gates via crafted prompts.

Disclosed 25 August 2026 · Record updated 13 September 2026

Impact

Remote execution of arbitrary Python code on agent hosts with bypass of human consent gates

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-78379