chiprook
← Security
SecurityOctober 4, 2026, 07:52

AWS Bedrock AgentCore fixed the same install_packages() injection bug twice

The Bedrock AgentCore Python SDK had an argument injection flaw in install_packages(): CVE-2026-12530 (v1.1.3–1.6.0) and a bypass of the first patch tracked as CVE-2026-16796 (fixed in v1.18.1). Both fixes were bypassable; the final fix uses shlex quoting and a tighter allowlist. BeyondTrust published its research on Sep 28.

AWS Bedrock AgentCore fixed the same install_packages() injection bug twice
#AWS#Bedrock#BeyondTrust
Read next
Security

Amazon Bedrock AgentCore SDK flaws exposed AWS credentials

AI

Bedrock AgentCore Runtime: Multi-Model Migration From ECS to Managed Orchestration

Software

AWS Reworks Bedrock AgentCore Runtime for Elastic Memory, Fast Cold Starts

Security

Malicious npm packages evade install-script defenses at runtime