CVE-2026-78379: Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's...

Added to the CISA Known Exploited Vulnerabilities catalog on 25 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.1.

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode a...

Required action: Review and patch if applicable to your AI infrastructure.