CVE-2026-18394

AWS · Strands Agents Tools

An incorrect authorization vulnerability in the http_request tool of Strands Agents Tools allows unauthorized data access.

Executive summary

Strands Agents Tools versions prior to 0.8.2 contain an authorization flaw that could lead to unauthorized information disclosure.

Vulnerability

The http_request tool suffers from an incorrect authorization flaw (CWE-863). The vulnerability requires user interaction to facilitate the unauthorized request, but it does not require authentication from the attacker.

Business impact

The vulnerability carries a CVSS score of 7.4, indicating high severity. Exploitation allows an attacker to perform unauthorized actions or access sensitive information via the http_request tool, which could result in data breaches or the compromise of internal service workflows.

Remediation

Immediate Action: Upgrade the Strands Agents Tools package to version 0.8.2 or higher to resolve the authorization logic error.

Proactive Monitoring: Review access logs for the http_request tool to identify any abnormal patterns or requests originating from unauthorized or unexpected sources.

Compensating Controls: Implement strict network segmentation and egress filtering to limit the potential impact if the tool is leveraged to reach sensitive internal endpoints.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for unauthorized data access, organizations using Strands Agents Tools should treat this as a high-priority update. Upgrading to version 0.8.2 is the most effective way to secure the http_request tool and prevent potential exploitation.