Amazon Bedrock AgentCore Python SDK Code Interpreter command-injection flaw (CVE-2026-12530)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-12530 in the Amazon Bedrock AgentCore Python SDK let crafted package names bypass the Code Interpreter helper's blocklist, creating command-execution risk inside AI sandboxes and exposing attached AWS credentials. The flaw affected versions 1.1.3 through 1.6.0 and let a package name become a shell command in the sandbox. AWS fixed it in 1.6.1 by replacing the blocklist with stricter validation.
Timeline
-
28.09.2026 03:00 2 articles · 1d ago
BeyondTrust reports command execution and AWS credential exposure in Amazon Bedrock AgentCore Code Interpreter
Initial DisclosureBeyondTrust says a crafted package name can bypass an incomplete character blocklist in Amazon Bedrock AgentCore's Python SDK Code Interpreter helper, turning install_packages() input into shell commands inside the sandbox and exposing temporary AWS credentials attached to the execution role. The advisory identifies CVE-2026-12530 and CVE-2026-16796, says the affected SDK range includes versions 1.1.3 through 1.6.0 and versions before 1.18.1, and notes that AWS later replaced the blocklist with stricter validation in 1.6.1, fixed the bypass in 1.18.1, and advised customers to upgrade and avoid untrusted or model-generated package names.
Show sources
- Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials — www.infosecurity-magazine.com — 29.09.2026 17:00
- Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials — www.infosecurity-magazine.com — 29.09.2026 17:00