Skip to content
HighVulnerability

CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution

Published
Record updated
View JSON

Summary

CVE-2026-104019 is an OS command injection flaw in the startup script that runs when a SageMaker Space starts in Amazon SageMaker Unified Studio. The script's network validation against project connections does not sanitize connection details, so under certain conditions arbitrary code can run in another project member's Space. In projects with Trusted Identity Propagation enabled, a user with contributor permissions or higher could obtain another member's temporary execution role credentials and call downstream services on that member's behalf.

Mitigation

Fixed in all supported SageMaker Distribution versions by sanitizing connection details during startup validation. The fix is deployed globally and applies to Spaces automatically on their next startup. Versions 2.8.x through 2.13.x are affected with no fix, as they are end of support.