A high-severity vulnerability, identified as CVE-2026-16796 with a CVSS score of 8.4, exists in the AWS Bedrock AgentCore Python SDK due to improper neutralization of argument delimiters in the install_packages method. This flaw allows a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. The issue arises from insufficient input validation in install_packages, which can be exploited by specially crafted package specifiers that bypass validation and achieve arbitrary command execution within the sandbox. A remote authenticated user who can influence the arguments to install_packages can execute arbitrary commands within the Code Interpreter sandbox environment, resulting in a high business impact. This vulnerability affects bedrock-agentcore versions less than 1.18.1.
We recommend you to update bedrock-agentcore to version 1.18.1.[/subscribe_to_unlock_form]
A high-severity vulnerability, identified as CVE-2026-16796 with a CVSS score of 8.4, exists in the AWS Bedrock AgentCore Python SDK due to improper neutralization of argument delimiters in the install_packages method. This flaw allows a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. The issue arises from insufficient input validation in install_packages, which can be exploited by specially crafted package specifiers that bypass validation and achieve arbitrary command execution within the sandbox. A remote authenticated user who can influence the arguments to install_packages can execute arbitrary commands within the Code Interpreter sandbox environment, resulting in a high business impact. This vulnerability affects bedrock-agentcore versions less than 1.18.1.
We recommend you to update bedrock-agentcore to version 1.18.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]