Impact
The http_request tool in Strands Agents Tools implements an authentication check that is incorrectly enforced, allowing a remote attacker to force the language model to send requests through a proxy controlled by the attacker and thereby expose credentials configured via HTTP_REQUEST_TOKEN_CONFIG. This flaw is a classic authorization bypass (CWE-863) that can result in the theft of authentication secrets. The CVSS score of 6.9 signals moderate severity, reflecting the potential impact on confidentiality while noting that it does not provide arbitrary code execution or full system compromise.
Affected Systems
AWS Strands Agents Tools versions prior to 0.8.2 are affected. The vulnerability resides in the http_request tool, part of the Strands Agents Tools package maintained by AWS. Any deployment that has not yet applied the 0.8.2 update remains vulnerable.
Risk and Exploitability
The flaw requires an attacker to influence the language model to route requests through a proxy under their control, which can be achieved remotely through crafted input. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the moderate CVSS rating and the potential to expose secret credentials warrant attention.
OpenCVE Enrichment