VYPR
Vendor

Strands Agents

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2026-19111HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.00

    Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit…

  • CVE-2026-18733HigAug 3, 2026
    risk 0.50cvss 8.8epss 0.00

    A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human…

  • CVE-2026-18394HigJul 31, 2026
    risk 0.41cvss 7.4epss 0.00

    Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To…

  • CVE-2026-15746MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request…