Server-Side Request Forgery in Amazon Bedrock AgentCore Starter Toolkit
CVE-2026-106032
What is CVE-2026-106032?
A server-side request forgery vulnerability exists in the OpenAPI schema processing within the OpenAPI content associated with the Bedrock Agent action group of Amazon's Bedrock AgentCore Starter Toolkit before version 0.3.14. This flaw may allow an authenticated remote actor, operating within the same AWS account, to exploit the environment of a user importing a Bedrock Agent. Consequently, this could enable the attacker to issue arbitrary outbound requests and gain unauthorized access to local files through specifically crafted external reference values. Users are strongly advised to upgrade to version 0.3.14 or migrate to the recommended @aws/agentcore npm CLI, as the Bedrock AgentCore Starter Toolkit is deprecated.
Affected Version(s)
bedrock-agentcore-starter-toolkit 0.1.4 <= 0.3.13
