AWS Bedrock AgentCore fixed the same install_packages() injection bug twice
The Bedrock AgentCore Python SDK had an argument injection flaw in install_packages(): CVE-2026-12530 (v1.1.3–1.6.0) and a bypass of the first patch tracked as CVE-2026-16796 (fixed in v1.18.1). Both fixes were bypassable; the final fix uses shlex quoting and a tighter allowlist. BeyondTrust published its research on Sep 28.
- CVE-2026-12530: argument injection in install_packages(), fixed in v1.6.1
- CVE-2026-16796: bypass of the first fix via pip extras syntax, closed in v1.18.1
- NVD scores: CVSS 3.1 7.3 and CVSS 4.0 8.4, still Awaiting Analysis
- v1.18.1 fix: shlex-based quoting plus a tighter allowlist for extras
Read next
Security