Vulnerability  ·  2026-10-08

AWS Bedrock AgentCore Starter Toolkit code injection on agent import → arbitrary code execution (CVE-2026-105812)

VulnerabilityHigh impactGlobalCVE-2026-105812
AWS disclosed via security bulletin 2026-127-AWS two issues in its Bedrock AgentCore Starter Toolkit: an improper-control-of-code-generation flaw (CVSS 9.0) that allows arbitrary code execution when a crafted agent is imported and run/deployed, and a companion SSRF (CVSS 5.7) in OpenAPI schema processing of the agent import feature. NVD published CVE-2026-105812 on 2026-10-06.
This is in the import/configuration path of AWS's managed agent runtime: a malicious or compromised 'agent as code' file becomes a supply-chain foothold executing in the developer's and deployment environment — exactly the agent-import attack surface a defender can't easily inventory, in one of the largest AI cloud platforms.
A crafted agent definition / configuration (imported agent file for CVE-2026-105812, or crafted Swagger/OpenAPI schema for the SSRF CVE-2026-106032) is processed by the Starter Toolkit's import functionality, which improperly controls code generation — leading to arbitrary code execution in the environment where the agent is imported and run, or server-side requests to attacker-chosen endpoints in the import environment.
bedrock-agentcore-starter-toolkit < 0.3.14 (also SSRF CVE-2026-106032 in OpenAPI schema processing, same package)
Update bedrock-agentcore-starter-toolkit to 0.3.14 or later (AWS security bulletin 2026-127-AWS); upgrade from PyPI release 0.3.14.
AWS Security Bulletin 2026-127-AWSNVD CVE-2026-105812NVD CVE-2026-106032
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →