AWS Strands Agents Tools

3 known vulnerabilities in AWS Strands Agents Tools, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-19111 CVSS 8.6 high Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before…
  • CVE-2026-18733 CVSS 7.5 high A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute…
  • CVE-2026-18394 CVSS 6.9 medium Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials…