Skip to content
AWSAWS-2026-040

Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import

Critical9.0CVE-2026-11393 · Published Sep 22, 2026

Bulletin ID:  2026-040-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/08/2026 11:45 AM PDT Description: The AWS AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. We identified CVE-2026-11393 in which improper neutralization of triple-quote characters during Python code generation may allow an authenticated user in the same AWS account to inject arbitrary Python code into the source file generated by the "agentcore add agent --type import" command. Specifically, the collaborationInstruction field of a Bedrock Agent collaborator association was interpolated into a triple-quoted Python docstring using single-quote escaping rather than triple-quote escaping. A user with bedrock:AssociateAgentCollaborator IAM permission could craft a collaborationInstruction value containing """ to break out of the docstring boundary in the generated main.py of the imported agent. If that generated file was subsequently executed - either via agentcore dev on the developer's local machine, or via agentcore deploy followed by agentcore invoke in the AgentCore Runtime environme...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Sep 26Severity: Unrated to Critical
Details and references

Bulletin ID:  2026-040-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/08/2026 11:45 AM PDT Description: The AWS AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. We identified CVE-2026-11393 in which improper neutralization of triple-quote characters during Python code generation may allow an authenticated user in the same AWS account to inject arbitrary Python code into the source file generated by the "agentcore add agent --type import" command. Specifically, the collaborationInstruction field of a Bedrock Agent collaborator association was interpolated into a triple-quoted Python docstring using single-quote escaping rather than triple-quote escaping. A user with bedrock:AssociateAgentCollaborator IAM permission could craft a collaborationInstruction value containing """ to break out of the docstring boundary in the generated main.py of the imported agent. If that generated file was subsequently executed - either via agentcore dev on the developer's local machine, or via agentcore deploy followed by agentcore invoke in the AgentCore Runtime environment - the injected Python would run with the credentials available in that context. Impacted versions: @aws/agentcore >= 0.4.0 AND preview versions >= 0.3.0-preview.7.0 and Resolution: This issue has been addressed in @aws/agentcore version 0.14.2 and preview version 1.0.0-preview.9 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. GA versions: npm install -g @aws/agentcore@latest Preview version: npm install -g @aws/agentcore@preview Customers who previously imported a Bedrock supervisor agent using agentcore add agent --type import on an affected version should: Upgrade the CLI to v0.14.2 / 1.0.0-preview.9 or later. Remove the affected agent from your project "agentcore remove agent " Re-run "agentcore add agent --type import" with the patched CLI to regenerate a clean main.py. Run "agentcore deploy --yes to" replace the deployed artifact on AWS. Workarounds: If an immediate upgrade is not possible, customers can manually inspect the generated main.py for any collaboratorInstruction values that contain """ sequences and replace them with \\"\\"\\" before deploying or running the agent locally. References: CVE-2026-11393 GHSA--m4x6-gwgp-4pm7 Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-040-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-11393 - Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import Bulletin ID:  2026-040-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/08/2026 11:45 AM PDT Description: The AWS AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. We identified CVE-2026-11393 in which improper neutralization of triple-quote characters during Python code generation may allow an authenticated user in the same AWS

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
NVD

More AWS advisories

All AWS
Advisory
Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
High8.8Sep 22
Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible...
High8.0Sep 22
HTTPS Fallback to HTTP in Graph Explorer
Medium5.9Sep 22
Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Critical9.8Sep 22
Authenticated SQL injection in the metrics-service retention policy subsystem of...
High8.1Sep 22
Excessive memory allocation in s2n-quic
Medium5.3Sep 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.