Two critical vulnerabilities discovered in Amazon Bedrock AgentCore's Python SDK could allow attackers to execute arbitrary commands within AI sandboxes and potentially access sensitive AWS credentials associated with affected workloads, according to Infosecurity Magazine.
The flaws, tracked as CVE-2026-12530 and CVE-2026-16796, were found in the SDK's Code Interpreter helper, which is used for package installation. BeyondTrust researchers detailed how a crafted package name could bypass security checks and execute commands inside the sandbox. The first vulnerability allowed attackers to read temporary credentials by exploiting an incomplete blocklist. Although AWS addressed this in version 1.6.1, a second vulnerability (CVE-2026-16796) emerged, abusing pip's package extras syntax to circumvent the updated validation. AWS fixed this in version 1.18.1.
The potential impact, including access to other AWS services, depended on the permissions granted to the execution role. AWS rated both vulnerabilities between 7.3 and 8.4 CVSS. Customers are advised to upgrade to version 1.18.1 or later and avoid passing untrusted package names to the helper. BeyondTrust also recommends limiting execution role permissions and monitoring Code Interpreter activity.
Source: Infosecurity Magazine