Code Generation Vulnerability in Amazon Bedrock AgentCore Starter Toolkit
CVE-2026-105812
8.8HIGH
What is CVE-2026-105812?
The Amazon Bedrock AgentCore Starter Toolkit is affected by an improper control of code generation in its agent import functionality. This flaw allows authenticated actors within the same account to execute arbitrary code by exploiting crafted configuration values, which are improperly incorporated into generated Python source. Users are advised to upgrade to version 0.3.14 and to re-import agents from affected versions to mitigate risks effectively. Additionally, it is crucial that all local and deployed output artifacts be replaced to ensure security.
Affected Version(s)
bedrock-agentcore-starter-toolkit 0.1.4 <= 0.3.13
