Improper Neutralization Vulnerability in AWS Bedrock AgentCore Python SDK
CVE-2026-16796
8.4HIGH
What is CVE-2026-16796?
The AWS Bedrock AgentCore Python SDK exhibits an improper neutralization issue within the install_packages() method which can potentially allow a remote authenticated user to execute arbitrary commands. This vulnerability arises when crafted package name arguments are processed, leading to security risks within the Code Interpreter sandbox environment. Users are highly urged to upgrade to version 1.18.1 or later to patch this vulnerability and ensure the integrity of their applications.
Affected Version(s)
bedrock-agentcore 1.18.1 0 < 1.18.1
