Code Injection Vulnerability in Bedrock AgentCore Starter Toolkit by AWS
CVE-2026-4269
5.8MEDIUM
What is CVE-2026-4269?
A vulnerability in Bedrock AgentCore Starter Toolkit prior to version v0.1.13 allows remote attackers to exploit a missing S3 ownership verification. This could enable code injection during the build process, ultimately leading to arbitrary code execution within the AgentCore Runtime. Users should ensure they upgrade to version v0.1.13 or higher to safeguard against this potential risk.
Affected Version(s)
Bedrock AgentCore Starter Toolkit 0.1.0 < 0.1.13
