HighVulnerability
CVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRF
- Published
- Record updated
Summary
The bedrock-agentcore-starter-toolkit, an AWS-maintained Python package distributed via GitHub and PyPI for importing Amazon Bedrock Agents into local environments, has two issues affecting versions >= 0.1.4 and <= 0.3.13. CVE-2026-105812 is a code injection flaw that could allow arbitrary code execution when a specially crafted agent is imported and then run or deployed. CVE-2026-106032 is an external reference handling flaw that could cause unintended network requests or local file access during agent import.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- InfoHow to keep AI agents within their permissionsSame vendor · BleepingComputer
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSame vendor · Dark Reading
- InfoSpaceXAI backs Omarchy, the controversial Linux distro, with $1.5 million in computeSame vendor · The Verge (AI)
- MediumAWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemmaSame vendor · CSO Online
- InfoAWS takes aim at runaway AI agent behavior with Strands BoxSame vendor · CSO Online