AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Summary
Security flaws in AI agent infrastructure from AWS, Google, and Vercel allowed attackers to trigger tools without the AI model actually running or authorizing the action. These vulnerabilities worked by bypassing the normal verification step between when a model decides to use a tool and when that tool is executed, potentially skipping safety checks like content filters.
Solution / Mitigation
AWS fixed the managed service automatically with no customer action needed. Google addressed the issues in ADK 2.5.0. Vercel patched @ai-sdk/harness-codex in version 1.0.29 and @ai-sdk/harness-opencode in version 1.0.28. However, the open-source Strands Python library that AWS AgentCore is built on still contains a comparable vulnerability; the researchers noted that a proposed fix via pull request was closed unmerged on June 19, 2026.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
First tracked: August 6, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 92%