{"data":{"id":"cffb20a5-f576-4dd4-ba56-c3bc383d59b2","title":"CVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRF","summary":"The bedrock-agentcore-starter-toolkit, an AWS-maintained Python package distributed via GitHub and PyPI for importing Amazon Bedrock Agents into local environments, has two issues affecting versions >= 0.1.4 and <= 0.3.13. CVE-2026-105812 is a code injection flaw that could allow arbitrary code execution when a specially crafted agent is imported and then run or deployed. CVE-2026-106032 is an external reference handling flaw that could cause unintended network requests or local file access during agent import.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://aws.amazon.com/security/security-bulletins/rss/2026-127-aws/","publishedAt":"2026-10-06T20:41:24.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["Amazon Bedrock","Amazon Bedrock AgentCore","bedrock-agentcore-starter-toolkit"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-06T20:41:24.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}