PT-2026-66844 · Aws · Strands-Agents-Tools

CVE-2026-18394

·

Publicado

2026-07-31

·

Atualizado

2026-07-31

CVSS v3.1

7.4

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Incorrect authorization in the http request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP REQUEST TOKEN CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure.
To remediate this issue, users should upgrade to version 0.8.2.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-18394

Produtos afetados

Strands-Agents-Tools