CyberRota Analysis
AI-GeneratedA prompt injection vulnerability in the shell tool of Amazon Strands Agents Tools prior to version 0.8.0 allows remote attackers to execute arbitrary operating system commands on the agent's host by manipulating the non_interactive parameter. This high-severity flaw poses significant risks, particularly for organizations utilizing these tools for automation and remote management. Users should prioritize upgrading to version 0.8.0 to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0.