Authorization Flaw in Strands Agents Tools from Strands
CVE-2026-18394
6.9MEDIUM
What is CVE-2026-18394?
An authorization flaw exists in the http_request tool of Strands Agents Tools prior to version 0.8.2. This vulnerability could be exploited by remote attackers who manipulate the Language Model (LLM) to direct requests through an attacker-controlled proxy, potentially exposing sensitive credentials configured via HTTP_REQUEST_TOKEN_CONFIG. Users are advised to upgrade to version 0.8.2 to mitigate the risk associated with this flaw.
Affected Version(s)
Strands Agents Tools 0 < 0.8.2
