Code Generation Vulnerability in Amazon Bedrock AgentCore Starter Toolkit
CVE-2026-105812

8.8HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105812?

The Amazon Bedrock AgentCore Starter Toolkit is affected by an improper control of code generation in its agent import functionality. This flaw allows authenticated actors within the same account to execute arbitrary code by exploiting crafted configuration values, which are improperly incorporated into generated Python source. Users are advised to upgrade to version 0.3.14 and to re-import agents from affected versions to mitigate risks effectively. Additionally, it is crucial that all local and deployed output artifacts be replaced to ensure security.

Affected Version(s)

bedrock-agentcore-starter-toolkit 0.1.4 <= 0.3.13

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.