What is CVE-2026-18394?
CVE-2026-18394 is an incorrect authorization vulnerability in the `http_request` tool of Strands Agents Tools before version 0.8.2, which could allow remote attackers to obtain credentials configured via `HTTP_REQUEST_TOKEN_CONFIG` by manipulating the LLM to route requests through actor-controlled proxy infrastructure. Users should update to the latest version to remediate this issue.
Azərbaycanca: CVE-2026-18394, Strands Agents Tools-un 0.8.2-dən əvvəlki versiyalarında `http_request` alətində səlahiyyət yoxlamasının düzgün aparılmaması səbəbindən uzaqdan hücum edənlərə `HTTP_REQUEST_TOKEN_CONFIG` ilə konfiqurasiya olunmuş etimadnamələri ələ keçirməyə imkan verir. Bu, hücumçunun LLM-i yönləndirərək sorğuları öz nəzarətindəki proxy infrastrukturu vasitəsilə yönləndirməsi ilə baş verir. İstifadəçilər bu problemi aradan qaldırmaq üçün aləti ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
What data can an attacker exploiting CVE-2026-18394 obtain in Strands Agents Tools?
The attacker can obtain credentials configured via `HTTP_REQUEST_TOKEN_CONFIG` by manipulating the LLM to route requests through actor-controlled proxy infrastructure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.