AWS has patched two vulnerabilities in its Bedrock AgentCore Starter Toolkit that could let a user with permission to modify an agent plant malicious content for another user to import. The flaws can lead to code execution, unintended network requests or the reading of local files.

Versions 0.1.4 through 0.3.13 of the open-source Python package are affected. AWS released version 0.3.14 with fixes and says agents imported using a vulnerable version must be imported again, with their generated files replaced both locally and in deployed environments.

The toolkit supplies command-line tools for bringing Amazon Bedrock Agents into local development environments. Its import process generates Python source from agent data. AWS’s advisories describe attacks by authenticated users within the same AWS account who have permission to change the relevant agent configuration.

The critical code-injection flaw, CVE-2026-105812, allows specially crafted agent data to enter generated Python code without safe encoding. Another user must import the modified agent and then run or deploy it for the injected code to execute.

The resulting code runs with the permissions of the local user or the AgentCore Runtime execution role. AWS rates the issue 9.0 under CVSS version 3.1. The advisory identifies action-group OpenAPI schemas, collaboration instructions and prompt overrides as agent fields that users should avoid importing from untrusted sources.

The second flaw, CVE-2026-106032, concerns external references inside an action group’s OpenAPI schema, which describes how an agent calls a service. An attacker able to modify that schema can cause the importing environment to make arbitrary outbound requests and read local files during the import itself.

Any information exposed through that route is limited by what the importing user’s environment can access. AWS classifies the issue as moderate, with a score of 5.7 under CVSS version 4.0. Unlike the code-injection issue, this behavior occurs during import without requiring the generated agent to be run afterward.

AWS recommends restricting permissions to create or update agent action groups and associate agent collaborators to trusted users. For teams unable to upgrade immediately, its workaround is to avoid importing agents whose relevant fields may have been changed by people they do not trust in the same account.

The Starter Toolkit has been deprecated since March 27. AWS recommends moving to the supported AgentCore CLI, distributed as the @aws/agentcore npm package. Its advisories say the replacement does not contain these flaws.

Teams maintaining forks or derivative versions must incorporate the patches as well. AWS credited security researcher Koh Jun Sheng with reporting the issues through coordinated disclosure.

Sources: AWS, AWS GitHub, AWS GitHub

–
By the Control Plane Editorial Team