CyberSecurity SEE

Amazon Bedrock AgentCore Vulnerabilities May Compromise AWS Credentials

Amazon Bedrock AgentCore Vulnerabilities May Compromise AWS Credentials

Two significant vulnerabilities were recently identified in the Amazon Bedrock AgentCore’s Python software development kit (SDK). These vulnerabilities have the potential to enable attackers to execute unauthorized commands within AI sandboxes and gain access to the AWS credentials affixed to the compromised workloads. The specific vulnerabilities were cataloged as CVE-2026-12530 and CVE-2026-16796.

According to a detailed technical report released by BeyondTrust on September 28, these vulnerabilities primarily affected the SDK’s Code Interpreter helper meant for package installations. Notably, an attacker only needed to manipulate the package name to bypass security measures within the AgentCore Python SDK and penetrate the Code Interpreter sandbox.

### SDK Flaws and Command Execution

The first vulnerability, CVE-2026-12530, impacted specific versions of AgentCore ranging from 1.1.3 to 1.6.0. This flaw permitted a maliciously crafted package name to circumvent an incomplete character blocklist, thereby converting the package name into a shell command executed within the AgentCore sandbox. Researchers from BeyondTrust discovered that, through this maneuver, they were capable of reading temporary credentials tied to the Code Interpreter’s execution role.

In response to the discovery, AWS promptly released version 1.6.1 of the SDK, addressing this vulnerability by enforcing a stricter validation rule to enhance security. However, BeyondTrust’s investigations revealed that the initial remedy could be exploited. This led to the identification of a second vulnerability, CVE-2026-16796. AWS noted that this flaw affects all SDK versions pre-dating 1.18.1, as it took advantage of pip’s package extras syntax to manipulate the validation process and gain entry for shell commands. AWS subsequently rectified this vulnerability in version 1.18.1 of the SDK.

### Conditions for Credential Exposure

BeyondTrust explained that the Firecracker isolation mechanism used for Code Interpreter sessions maintained its integrity, which meant that the vulnerabilities resided specifically in the SDK helper responsible for constructing the installation command. Credential exposure hinged on three preconditions: input influenced by an attacker reaching the function install_packages(), a vulnerable version of the SDK, and a custom Code Interpreter with an attached execution role.

### AWS Credentials and Their Widespread Impact

The aftermath of successfully executing code within the sandbox depended on the privileges granted to the execution role. BeyondTrust highlighted that these privileges could potentially extend to other AWS services if permissions were overly permissive. Furthermore, the activity generated by the attacker could be camouflaged as legitimate application activity in AWS logs, making it more challenging to detect malicious maneuvers.

Input for the exploit could originate from various sources. This includes user-supplied package names, untrusted content processed by an agent, or dependency files sourced from a compromised repository.

AWS assigned both vulnerabilities a score of 7.3 under the Common Vulnerability Scoring System (CVSS) version 3.1 and an even higher score of 8.4 under CVSS version 4.0. In light of these findings, AWS has urged its customers to upgrade to version 1.18.1 or later and advised against passing any untrusted or model-generated package names to the SDK helper.

In addition, BeyondTrust made recommendations aimed at bolstering security measures. They advised avoiding the assignment of execution roles to code that does not necessitate AWS access. For scenarios where AWS access is required, it is prudent to tightly scope identity and access management (IAM) permissions. Monitoring Code Interpreter activity was also underscored as an essential step, echoing a recent report from Sophos that emphasized the importance of limiting the access of AI agents.

As the security landscape continues to evolve, organizations leveraging these technologies must remain vigilant and proactive in updating and securing their systems against emerging threats. The identification and rectification of these vulnerabilities serve as a reminder of the ongoing challenges in maintaining cybersecurity, especially as more applications and services become intertwined with AI functionalities.

Source link

Exit mobile version