CVE-2026-78379
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
25/08/2026
Last modified:
26/08/2026
Description
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument through the batch tool. To remediate this issue, users should upgrade to version 0.8.5 or later.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL
Base Score 3.x
8.10
Severity 3.x
HIGH



