Skip to main content
CybersecurityVulnerability Management

AWS Credentials at Risk as Flaws in Amazon Bedrock AgentCore Expose Command Execution

A clean workstation setup with a laptop on a neutral surface, surrounded by blurred technical equipment.

"package name was enough to get commands past the AgentCore Python SDK and into the Code Interpreter sandbox," BeyondTrust wrote in its technical write-up on September 28.

CVE-2026-12530: package-name turns into shell commands

BeyondTrust discovered that a crafted package name could bypass an incomplete character blocklist in the AgentCore Python SDK and become a shell command run inside the Code Interpreter sandbox. Tracked as CVE-2026-12530, the flaw affected AgentCore SDK versions 1.1.3 through 1.6.0. The researchers reported that, after getting commands to execute inside the sandbox, they were able to read temporary credentials belonging to the Code Interpreter's execution role.

AWS addressed CVE-2026-12530 in AgentCore version 1.6.1 by replacing the blocklist with a stricter validation rule. BeyondTrust, however, found that the initial blocklist change could be bypassed, which led to a second, related finding.

CVE-2026-16796: pip extras syntax bypasses validation

The second issue, CVE-2026-16796, abused pip's package extras syntax to pass shell commands through the SDK's validation. AWS lists this second flaw as affecting all SDK versions before 1.18.1 and released a fix in version 1.18.1. BeyondTrust traced both issues back to the SDK helper that builds the installation command for the Code Interpreter's package installation flow.

Impact on AWS credentials, execution roles, and logs

The exposure of AWS credentials required three conditions to line up: attacker-influenced input reaching the install_packages() helper, a vulnerable AgentCore SDK version, and a custom Code Interpreter configured with an execution role attached. Once code executed inside the sandbox, the resulting access depended on the permissions granted to that execution role; BeyondTrust noted those permissions could extend to other AWS services where permissions were excessive.

BeyondTrust also warned that an attacker's activity could appear in AWS logs as legitimate application behavior, making detection harder. The researchers observed that input vectors could include user-supplied package names, untrusted content processed by an agent, or dependency files hosted in an untrusted repository.

Separately, BeyondTrust said the Firecracker isolation used for Code Interpreter sessions held during their testing; the weakness was not the sandbox itself but the SDK helper that assembled the package-install command.

Recommendations from AWS and BeyondTrust

  • AWS advised customers to upgrade to AgentCore SDK version 1.18.1 or later and recommended not passing untrusted or model-generated package names to the install helper.
  • BeyondTrust recommended avoiding execution roles where code running in a sandbox needs no AWS access, tightly scoping identity and access management (IAM) permissions where roles are required, and monitoring Code Interpreter activity. The company noted these steps echo a recent Sophos report on limiting AI agents' access.
  • AWS scored both vulnerabilities 7.3 under CVSS 3.1 and 8.4 under CVSS 4.0.

What this means for technologists, procurement leaders, and adversaries

  • Technologists and security teams should assume helper code that constructs shell commands is a high-risk surface: upgrade AgentCore to 1.18.1 or later, stop passing untrusted or model-generated package names into install_packages(), and monitor Code Interpreter sessions for anomalous activity, as recommended by BeyondTrust and AWS.
  • Procurement leaders and those responsible for cloud configurations should review whether custom Code Interpreter instances require execution roles at all; BeyondTrust explicitly advised avoiding execution roles when code needs no AWS access and tightly scoping IAM permissions where access is necessary.
  • Adversaries with the ability to influence package names, dependency files, or other agent-processed content could attempt to exploit these exact vectors on vulnerable SDK versions; the researchers demonstrated that crafted package names and pip extras syntax were sufficient to pass validation and reach the execution environment when conditions aligned.

The vulnerabilities highlight a narrow but consequential pathway from innocuous inputs — package names and dependency metadata — to command execution and credential disclosure when helper code validates input imperfectly. AWS and BeyondTrust have supplied fixes and configuration guidance; the remaining task for operators is practical: upgrade the SDK, remove unnecessary execution roles, and treat package-install pathways as code-execution boundaries rather than benign metadata fields.

Original reporting: https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/