OS Command Injection in Amazon SageMaker Distribution
CVSS 4.0
9.3critical
EPSS
—
Published
()
Modified
AI analysis
Amazon SageMaker Distribution has an OS command injection flaw in the Studio Space startup validation script used by Amazon SageMaker Unified Studio. An authenticated remote user who already has project contributor permissions can trigger it with a crafted connection resource property that is interpolated into a shell invocation without neutralization. Successful exploitation can run arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials. Affected releases are 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3. No public proof of concept is known and the issue is not listed in CISA KEV.
What to do: Upgrade Amazon SageMaker Distribution to 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3 for the minor line in use, and move any end-of-support minor line to a supported line because no patch will be released for it. In Amazon SageMaker Unified Studio, restart Studio Spaces after the patched images are deployed so they adopt the latest patch of their minor line. Review project contributor membership and look for unexpected connection resources or unusual activity in other members' Studio Spaces.
Affected
Amazon SageMaker Distribution (as used by Amazon SageMaker Unified Studio)
2.x before 2.14.12; 3.x before 3.9.12; 4.0.x before 4.0.11; 4.1.x before 4.1.11; 4.2.x before 4.2.8; 4.3.x before 4.3.5; 4.4.x before 4.4.3
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property that is interpolated into a shell invocation without neutralization. To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use. Users on minor lines that have reached end of support must move to a supported minor line, because no patched version will be released for those lines. In Amazon SageMaker Unified Studio, Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed, so no version selection is required.
AWS patched four Loom and SageMaker flaws enabling auth bypass, token theft, SSRF, and cross-user command execution.
AWS fixed four vulnerabilities in the open-source Loom AI agent platform and Amazon SageMaker Unified Studio, disclosed on October 2, 2026. CVE-2026-103956 can give any network client full administrative control of Loom when no identity provider is configured. CVE-2026-103957 and CVE-2026-103958 let users with mcp:write or a2a:write leak OAuth2 tokens or reach internal services, including credential endpoints. CVE-2026-104019 is command injection in SageMaker Space startup scripts that can run code in another member's environment and steal temporary role credentials.
AWS patched Loom AI-agent flaws that can bypass authentication, leak OAuth tokens, and expose cloud credentials.
AWS patched four flaws affecting its open-source Loom AI-agent platform and Amazon SageMaker Unified Studio, disclosed in Security Bulletin 2026-124-AWS on October 2, 2026. CVE-2026-103956 let any network client gain full administrative access to Loom deployments before 1.6.1 that had no identity provider. CVE-2026-103957 and CVE-2026-103958, fixed in Loom 1.7.0, let users with mcp:write or a2a:write leak OAuth secrets or tokens and read internal services, including cloud credential endpoints. CVE-2026-104019 is a command-injection bug in SageMaker Studio Space startup that could steal another project member's temporary credentials; patched images apply on restart.