What happened
AWS disclosed CVE-2026-107322 (CVSS 7.8) on 2026-10-08: the databases-on-aws plugin's incomplete list of disallowed inputs allows a remote unauthenticated actor to inject OS commands through a crafted database command value introduced in the agent context. Execution occurs only if the agent later invokes the local helper, at which point commands run with the helper process's permissions. Reported by Shay Sakazi via coordinated disclosure; fixed in 1.7.1.
Why it matters
This is an agentic tool-argument command injection in AWS's official AI-agent plugin suite: an attacker who can plant content an agent ingests (injected prompt/tool input from an untrusted document, web page, or email) can escalate to host command execution inside an agent-assisted database workflow — turning a prompt-injection primitive into native code execution on the operator's machine with the agent's cloud credentials.
Attack vector
A remote unauthenticated actor supplies crafted content that an agent ingests (a crafted database command value placed in the agent context). If the agent subsequently invokes the local helper with that value, the incomplete denylist of disallowed inputs allows operating-system command execution on the host, running with the permissions of the process running the helper and any AWS credentials it holds.
Affected systems
databases-on-aws plugin versions 1.0.0 through 1.7.0 (fixed in 1.7.1, available from the marketplace/main since 2026-08-26; pinned repos must use commit 8b13a503746a4ebb0402b936645163224058bde3 or later)
Mitigation
Upgrade databases-on-aws to 1.7.1+. If unable to upgrade, avoid the optional psql connection-helper command path, use manually reviewed SQL or the DSQL MCP server instead, run the agent/helper as an unprivileged OS user with a scoped (ideally read-only) dsql IAM role, and rotate any credentials accessible to a potentially-compromised helper host. AWS bulletin 2026-130-AWS.