strands-agents-tools is vulnerable to Server-Side Request Forgery (SSRF)
65
Medium Risk
The elasticsearch_memory tool exposes its Elasticsearch connection parameters (es_url, cloud_id, api_key) as fields the language model can control through the tool schema. When a caller omits api_key, the tool falls back to the operator's ELASTICSEARCH_API_KEY environment variable, and because the destination host is also model-controllable, a crafted prompt can direct the tool to connect to an actor-controlled server. In that case the operator's Elasticsearch credential is sent in the Authorization header to the attacker host, disclosing it. The fix restricts the connection parameters so the model can no longer redirect requests to leak the stored credential.
You are affected if you are using a version that falls within the vulnerable range and you use the elasticsearch_memory tool.
strands-agents-tools is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.2.11 - 0.6.0.
Upgrade the strands-agents-tools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant