One Chat Prompt Could Expose AWS AI Agent Credentials, Researchers Find
Researchers at Zenity Labs have detailed a weakness in Amazon Bedrock AgentCore, the service used to host AI agents. In their scenario, a user chatting with an agent on a website asks it to fetch a credential endpoint. The agent obliges, and returns data from the Instance Metadata Service (IMDS), which describes the cloud virtual machine it runs on and can include security tokens. At the time of the research in late 2025, AgentCore still used the older IMDSv1, which offers fewer protections than IMDSv2.
The data returned included the agent's temporary credentials. Using them from his own machine, the attacker in the researchers' example listed other agents in the same AWS region, pulled their container images from Amazon Elastic Container Registry and inspected the source code. The credentials also revealed memory resources used by agents, which allowed users and their conversations to be extracted.
Zenity Labs researchers Tamir Ishay Sharbat and Lana Salameh say an outsider with only chat access to one exposed agent could send a single prompt, extract the credentials and take over all AgentCore agents in the same AWS account and region. They attribute the problem to the Firecracker MicroVM used by AgentCore, which did not provide sufficient network isolation, letting the agent be steered into a server-side request forgery (SSRF) attack. The findings were disclosed to AWS in December 2025.
This article covers only the opening of the original report.