// AWSMEDIUM
AWS disclosed CVE-2026-15746, an SSRF vulnerability in the strands-agents-tools package (an open-source Python SDK for building AI agents). The elasticsearch_memory tool allows large language models to control connection parameters, enabling a crafted prompt to exfiltrate the operator's Elasticsearch API key to an attacker-controlled server. AWS recommends upgrading to version 0.7.0 or later and rotating all ELASTICSEARCH_API_KEY credentials as a precautionary measure.
// Get alerts for AWS