Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106032 | 1 Aws | 1 Bedrock-agentcore-starter-toolkit | 2026-10-07 | 5.7 Medium |
| Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated remote actor in the same AWS account to cause the environment of a user importing a Bedrock Agent to issue arbitrary outbound requests and read arbitrary local files, via crafted external reference values in the OpenAPI content associated with a Bedrock Agent action group. To remediate this issue, users should upgrade to version 0.3.14. Note that bedrock-agentcore-starter-toolkit is deprecated. The @aws/agentcore npm CLI is the supported replacement and does not contain this issue. Migration to @aws/agentcore is the recommended long-term path. | ||||
| CVE-2026-105812 | 1 Aws | 1 Bedrock-agentcore-starter-toolkit | 2026-10-07 | 9 Critical |
| Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated Python source without safe literal encoding. To remediate this issue, users should upgrade to version 0.3.14. Because this issue persists into generated source, upgrading alone is not sufficient: agents imported with an affected version must be re-imported with version 0.3.14 or later and their local and deployed output artifacts replaced. | ||||
| CVE-2026-16796 | 1 Aws | 2 Bedrock-agentcore, Bedrock-agentcore 1.18.1 | 2026-07-28 | 7.3 High |
| Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to the patched version 1.18.1. | ||||
| CVE-2026-15737 | 1 Aws | 1 Bedrock-agentcore | 2026-07-16 | 5.7 Medium |
| AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a local authenticated user with access to CloudWatch Logs to access raw user prompts and agent responses containing sensitive data via span attributes. The SDK wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, exposing sensitive content to any principal with log read access. We recommend you upgrade to version 1.5.1 or later. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups. | ||||
| CVE-2026-12530 | 1 Aws | 1 Bedrock-agentcore | 2026-06-18 | 7.3 High |
| Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to version 1.6.1. | ||||
Page 1 of 1.