Impact
This vulnerability occurs in the python_repl tool of Amazon Strands Agents Tools. Prior to version 0.8.5, inputs used for large‑language‑model prompting are not properly neutralized. This flaw allows a remote actor to inject a crafted prompt that forwards the non_interactive_mode keyword argument to the batch tool, bypassing the human consent gate. A successful exploit can lead to arbitrary Python code execution on the host running the agent, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Affected products are Amazon Strands Agents Tools, versions before 0.8.5. Systems that deploy the python_repl function are at risk unless they have upgraded to 0.8.5 or later.
Risk and Exploitability
The CVSS score of 9.2 signals a high‑severity remote code execution threat. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, so the current likelihood of exploitation is unknown. Based on the description, it is inferred that an attacker requires the ability to send prompts to the python_repl tool, which could be achieved through remote interfaces or interactions with the agent. Given the severity and the potential for unrestricted code execution, urgent review and mitigation are recommended.
OpenCVE Enrichment