Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials
Two Amazon Bedrock AgentCore SDK flaws (CVE-2026-12530, CVE-2026-16796) enabled command execution inside AI sandboxes and exposure of attached AWS credentials; patched in 1.18.1.
BeyondTrust disclosed two flaws in Amazon Bedrock AgentCore's Python SDK Code Interpreter package-installation helper: CVE-2026-12530 (AgentCore 1.1.3-1.6.0) let a crafted package name bypass an incomplete character blocklist to execute shell commands in the sandbox, while CVE-2026-16796 abused pip extras syntax to bypass the first fix, affecting all versions before 1.18.1. Attackers could then read temporary credentials belonging to the Code Interpreter's execution role, with impact depending on the role's IAM permissions, and their activity could look legitimate in AWS logs. AWS fixed both issues in SDK 1.18.1 with stricter validation, and the underlying Firecracker sandbox isolation held. AWS scored both vulnerabilities CVSS 3.1 7.3 and CVSS 4.0 8.4, advising upgrades and never passing untrusted or model-generated package names to the helper.
- CVE-2026-12530 bypassed SDK blocklist via crafted package names for sandbox command execution
- CVE-2026-16796 abused pip extras syntax to bypass the first fix; patched in 1.18.1
- Attackers could read Code Interpreter execution role credentials, appearing as legitimate AWS activity
- AWS scored both flaws CVSS 7.3 (v3.1) and 8.4 (v4.0)
Vulnerabilities mentionedAll →
- CVE-2026-125308.4<1%Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a…published
- CVE-2026-167968.4<1%Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote…
Full article401 words · extracted from infosecurity-magazine.com · click to collapse
Two vulnerabilities in Amazon Bedrock AgentCore's Python software development kit (SDK) could have let attackers execute commands inside AI sandboxes and reach the AWS credentials attached to the affected workloads.
The flaws affected the SDK's Code Interpreter helper for package installation and were tracked as CVE-2026-12530 and CVE-2026-16796.
In a technical write-up published on September 28, BeyondTrust said package name was enough to get commands past the AgentCore Python SDK and into the Code Interpreter sandbox.
SDK Flaws Turn Package Names Into Command Execution
The first vulnerability, CVE-2026-12530, affected AgentCore versions 1.1.3 through 1.6.0 and allowed a crafted package name to bypass an incomplete character blocklist. BeyondTrust found that this could turn the package name into a shell command executed inside the AgentCore sandbox.
The researchers then read temporary credentials belonging to the Code Interpreter's execution role. AWS addressed the flaw in version 1.6.1 by replacing the blocklist with a stricter validation rule.
However, BeyondTrust found that the first fix could itself be bypassed. CVE-2026-16796, which AWS lists as affecting all SDK versions before 1.18.1, abused pip's package extras syntax to pass shell commands through the validation. AWS fixed the second vulnerability in version 1.18.1.
Read more on AI agent security: NCSC Urges Stronger Controls for Agentic AI Systems
BeyondTrust said the Firecracker isolation used for CodeInterpreter sessions held. The weakness lay in the SDK helper that built the installation command.
Credential exposure required three conditions: attacker-influenced input reaching install_packages(), a vulnerable SDK version and a custom Code Interpreter with an execution role attached.
AWS Credentials Expand the Potential Impact
Once code ran inside the sandbox, the impact depended on the permissions granted to the execution role, which BeyondTrust said could extend to other AWS services where permissions were excessive.
BeyondTrust noted that the attacker's activity could look like legitimate application activity in AWS logs.
The company explained that input could come from user-supplied package names, untrusted content an agent processed or dependency files in an untrusted repository.
AWS scored both vulnerabilities 7.3 under CVSS 3.1 and 8.4 under CVSS 4.0. AWS advised customers to upgrade to version 1.18.1 or later and not to pass untrusted or model-generated package names to the helper.
BeyondTrust also recommended avoiding execution roles where code needs no AWS access, tightly scoping identity and access management (IAM) permissions where it does and monitoring Code Interpreter activity, echoing a recent Sophos report on limiting AI agents' access.