All 4 CVE vulnerabilities found in strands-agents-tools, with AI-generated Chinese analysis, references, and POCs.
Vendor: Amazon
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-78379 | Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools CWE-1427 | 8.1 | High | 2026-08-25 |
| CVE-2026-19111 | Insecure direct object reference in Strands Agents Tools memory tool namespace isolation CWE-639 | 8.1 | High | 2026-08-06 |
| CVE-2026-18733 | Prompt injection bypasses shell tool consent gate in Strands Agents Tools CWE-1427 | 8.8 | High | 2026-08-03 |
| CVE-2026-15746 | Credential disclosure in Strands Agents Tools elasticsearch_memory tool CWE-918 | 6.5 | Medium | 2026-07-15 |
All 4 known CVE vulnerabilities affecting strands-agents-tools with full Chinese analysis, references, and POCs where available.