strands-agents-tools is vulnerable to Improper Neutralization of Input Used for LLM Prompting
81
High Risk
The python_repl tool requires operator approval through a human consent gate before executing Python on the agent host. When both the batch and python_repl tools are registered on the same agent, a crafted prompt can pass non_interactive_mode as a keyword argument through the batch tool, causing python_repl to run without triggering consent. This enables arbitrary Python code execution on the host. The fix makes non_interactive_mode read only from the STRANDS_NON_INTERACTIVE environment variable so it cannot be set through prompt input.
You are affected if you are using a version that falls within the vulnerable range and you register both the batch and python_repl tools on an agent that processes untrusted content.
strands-agents-tools is vulnerable to Improper Neutralization of Input Used for LLM Prompting in versions 0.0.1 - 0.8.4.
Upgrade the strands-agents-tools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.