Two Flaws in Amazon Bedrock AgentCore SDK Could Have Leaked AWS Credentials
Security researchers at BeyondTrust discovered two vulnerabilities in Amazon Bedrock AgentCore's Python SDK that could allow attackers to execute commands inside AI sandbox environments and access AWS credentials tied to those workloads. The flaws, tracked as CVE-2026-12530 and CVE-2026-16796, both involved the SDK's Code Interpreter helper used for installing software packages.
The first flaw let attackers craft a package name that slipped past an incomplete filter and was then run as a shell command inside the sandbox, exposing temporary credentials for the sandbox's execution role. AWS fixed this in version 1.6.1, but BeyondTrust found the fix could be bypassed using a different technique involving package naming syntax, tracked as the second CVE. AWS patched this second issue in version 1.18.1.
Exploiting either flaw required specific conditions: untrusted input reaching the package installation function, a vulnerable SDK version, and a custom Code Interpreter with an attached execution role. Once triggered, the impact depended on what permissions that role held, potentially extending to other AWS services. BeyondTrust also warned that such attacks could blend in with normal activity in AWS logs, making detection harder. AWS has rated both issues as high severity and recommends upgrading immediately.