Tag: cve 2026 18236
1 article

Agent Flaws in AWS, Google, Vercel Expose Tools to Forged Instructions
Critical flaws in AWS, Google, and Vercel's agent systems, dubbed CoreBreak, allow attackers to forge instructions by exploiting how tool calls are validated, potentially letting malicious data masquerade as authorized model commands. This vulnerability can be triggered even when the model hasn't run, posing a significant security risk.