漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Prompt injection bypasses shell tool consent gate in Strands Agents Tools
Vulnerability Description
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate.
To remediate this issue, users should upgrade to version 0.8.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1427
Vulnerability Title
Amazon Strands Agents Tools 提示词注入漏洞
Vulnerability Description
Amazon Strands Agents Tools是美国Amazon公司开源的一款人工智能智能体工具。 Amazon Strands Agents Tools 0.8.0之前版本存在提示词注入漏洞,该漏洞源于shell工具中的提示注入问题,可能导致远程攻击者通过特制提示将non_interactive参数设置为true,绕过人工同意门,在代理主机上执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A