A vulnerability categorized as critical has been discovered in AWS Strands Agents Tools up to 0.7.x. The affected element is an unknown function of the component Shell Tool. Executing a manipulation of the argument non_interactive can lead to injection.
This vulnerability is handled as CVE-2026-18733. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.