Find notable cyber news and cases, enriched with sources, timelines, and signals.

Amazon Bedrock AgentCore Python SDK Code Interpreter command-injection flaw (CVE-2026-12530)

Vulnerability
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-12530 in the Amazon Bedrock AgentCore Python SDK let crafted package names bypass the Code Interpreter helper's blocklist, creating command-execution risk inside AI sandboxes and exposing attached AWS credentials. The flaw affected versions 1.1.3 through 1.6.0 and let a package name become a shell command in the sandbox. AWS fixed it in 1.6.1 by replacing the blocklist with stricter validation.

Timeline

  1. 28.09.2026 03:00 2 articles · 1d ago

    BeyondTrust reports command execution and AWS credential exposure in Amazon Bedrock AgentCore Code Interpreter

    Initial Disclosure

    BeyondTrust says a crafted package name can bypass an incomplete character blocklist in Amazon Bedrock AgentCore's Python SDK Code Interpreter helper, turning install_packages() input into shell commands inside the sandbox and exposing temporary AWS credentials attached to the execution role. The advisory identifies CVE-2026-12530 and CVE-2026-16796, says the affected SDK range includes versions 1.1.3 through 1.6.0 and versions before 1.18.1, and notes that AWS later replaced the blocklist with stricter validation in 1.6.1, fixed the bypass in 1.18.1, and advised customers to upgrade and avoid untrusted or model-generated package names.

    Show sources