Tag: command execution
2 articles

AWS Credentials at Risk as Flaws in Amazon Bedrock AgentCore Expose Command Execution
A shocking vulnerability in Amazon Bedrock's AgentCore Python SDK could have put your AWS credentials at risk, allowing hackers to execute commands and access sensitive data. A simple crafted package name was all it took to bypass security measures and get commands running inside the Code Interpreter sandbox.

Cursor Security Flaw Enables Pre-Trust Command Execution
A security flaw in Cursor allowed hackers to run malicious commands on a developer's machine before they even had a chance to trust the repository, thanks to a vulnerability in its isolated worktree feature. Fortunately, a fix was swiftly rolled out just three days after Manifold Security reported the issue on July 20.