Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Prompt injection bypasses shell tool consent gate in Strands Agents Tools
Vulnerability Description
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate.
To remediate this issue, users should upgrade to version 0.8.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1427
Vulnerability Title
Amazon Strands Agents Tools 提示词注入漏洞
Vulnerability Description
Amazon Strands Agents Tools是美国Amazon公司开源的一款人工智能智能体工具。 Amazon Strands Agents Tools 0.8.0之前版本存在提示词注入漏洞,该漏洞源于shell工具中的提示注入问题,可能导致远程攻击者通过特制提示将non_interactive参数设置为true,绕过人工同意门,在代理主机上执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A