Security News

Two Flaws in Amazon Bedrock AgentCore SDK Could Have Leaked AWS Credentials

Infosecurity Magazine · 30 Sept 2026
Key Takeaway If your business uses Amazon Bedrock AgentCore, upgrade to SDK version 1.18.1 or later immediately and avoid feeding untrusted or AI-generated package names into automated installation processes.

Security researchers at BeyondTrust discovered two vulnerabilities in Amazon Bedrock AgentCore's Python SDK that could allow attackers to execute commands inside AI sandbox environments and access AWS credentials tied to those workloads. The flaws, tracked as CVE-2026-12530 and CVE-2026-16796, both involved the SDK's Code Interpreter helper used for installing software packages.

The first flaw let attackers craft a package name that slipped past an incomplete filter and was then run as a shell command inside the sandbox, exposing temporary credentials for the sandbox's execution role. AWS fixed this in version 1.6.1, but BeyondTrust found the fix could be bypassed using a different technique involving package naming syntax, tracked as the second CVE. AWS patched this second issue in version 1.18.1.

Exploiting either flaw required specific conditions: untrusted input reaching the package installation function, a vulnerable SDK version, and a custom Code Interpreter with an attached execution role. Once triggered, the impact depended on what permissions that role held, potentially extending to other AWS services. BeyondTrust also warned that such attacks could blend in with normal activity in AWS logs, making detection harder. AWS has rated both issues as high severity and recommends upgrading immediately.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.