CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools

Published 2026-09-09T21:30:11Za9e567736741c2006ec077e5a66c4bd1cb64ebf00a5f80517c59a51acf6874ac

Source metadata

Publication date
2026-09-09T21:30:11Z
Source identifier
ae180075751af233e84489d9f5e9e0761da8f598
Public record ID
record:sha256:a9e567736741c2006ec077e5a66c4bd1cb64ebf00a5f80517c59a51acf6874ac

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
a9e567736741c2006ec077e5a66c4bd1cb64ebf00a5f80517c59a51acf6874ac
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.