CVE-2026-11393 with a CVSS score of 9.0 is a vulnerability affecting @aws/agentcore versions >= 1.0.0-preview.1, < 1.0.0-preview.9 affecting @aws/agentcore versions and deployed it to AWS remain exposed on every agent invocation until they regenerate and redeploy the agent using a patched CLI version affecting @aws/agentcore versions >= 0.4.0, < 0.14.2 affecting @aws/agentcore versions >= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0 in the @aws/agentcore CLI that allows for code injection via improper triple-quote escaping, specifically in collaborationInstruction values stored in Bedrock Agent collaborator metadata. Affected versions include @aws/agentcore >= 0.4.0 AND <= 0.14.1, preview >= 0.3.0-preview.7.0 AND <= 1.0.0-preview.8. An authenticated AWS user with the bedrock:AssociateAgentCollaborator IAM permission can associate a collaborator agent carrying a crafted collaborationInstruction with a supervisor agent, allowing for arbitrary code execution when the generated file is loaded or deployed. This vulnerability exists in the rating block's custom icon rendering component and allows for exploitation via the environment template management API. Customers who have already imported a supervisor agent using an affected version remain exposed on every agent invocation until they regenerate and redeploy the agent using a patched CLI version.
We recommend you to update @aws/agentcore to version 0.14.2 or 1.0.0-preview.9.[/subscribe_to_unlock_form]
CVE-2026-11393 with a CVSS score of 9.0 is a vulnerability affecting @aws/agentcore versions >= 1.0.0-preview.1, < 1.0.0-preview.9 affecting @aws/agentcore versions and deployed it to AWS remain exposed on every agent invocation until they regenerate and redeploy the agent using a patched CLI version affecting @aws/agentcore versions >= 0.4.0, < 0.14.2 affecting @aws/agentcore versions >= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0 in the @aws/agentcore CLI that allows for code injection via improper triple-quote escaping, specifically in collaborationInstruction values stored in Bedrock Agent collaborator metadata. Affected versions include @aws/agentcore >= 0.4.0 AND <= 0.14.1, preview >= 0.3.0-preview.7.0 AND <= 1.0.0-preview.8. An authenticated AWS user with the bedrock:AssociateAgentCollaborator IAM permission can associate a collaborator agent carrying a crafted collaborationInstruction with a supervisor agent, allowing for arbitrary code execution when the generated file is loaded or deployed. This vulnerability exists in the rating block's custom icon rendering component and allows for exploitation via the environment template management API. Customers who have already imported a supervisor agent using an affected version remain exposed on every agent invocation until they regenerate and redeploy the agent using a patched CLI version.
We recommend you to update @aws/agentcore to version 0.14.2 or 1.0.0-preview.9.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]