Skip to content
AWSAWS-2026-044

Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK...

UnratedCVE-2026-12530 · Published Sep 22, 2026

Bulletin ID:  2026-044-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/17/2026 14:15 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source SDK that enables developers to build, deploy, and manage agents on AWS Bedrock AgentCore. We identified CVE-2026-12530 , an issue in the install_packages() method of the Code Interpreter client. The method applied an incomplete blocklist to sanitize package name arguments before constructing a 'pip install' shell command executed within the Code Interpreter sandbox. This allowed crafted package name arguments to bypass validation - most critically, pip's '--index-url' flag, which could redirect package resolution to an third-party-controlled PyPI server, and the '-r' flag, which could read and expose arbitrary sandbox files. Impacted versions:  AWS Bedrock AgentCore Python SDK (bedrock-agentcore) versions >= 1.1.3 and Resolution: This issue has been addressed in bedrock-agentcore version 1.6.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you are...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID:  2026-044-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/17/2026 14:15 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source SDK that enables developers to build, deploy, and manage agents on AWS Bedrock AgentCore. We identified CVE-2026-12530 , an issue in the install_packages() method of the Code Interpreter client. The method applied an incomplete blocklist to sanitize package name arguments before constructing a 'pip install' shell command executed within the Code Interpreter sandbox. This allowed crafted package name arguments to bypass validation - most critically, pip's '--index-url' flag, which could redirect package resolution to an third-party-controlled PyPI server, and the '-r' flag, which could read and expose arbitrary sandbox files. Impacted versions:  AWS Bedrock AgentCore Python SDK (bedrock-agentcore) versions >= 1.1.3 and Resolution: This issue has been addressed in bedrock-agentcore version 1.6.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you are unable to upgrade immediately, avoid passing any user-supplied or externally-influenced strings directly to install_packages(). Restrict calls to a fixed, hardcoded list of approved package names within your application code. References: CVE-2026-12530 GHSA-6rfw-mq36-jm8h Acknowledgement: We would like to thank Sergio Garcia for collaborating on this issue through the coordinated vulnerability disclosure process. Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-044-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() Bulletin ID:  2026-044-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/17/2026 14:15 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source SDK that enables developers to build, deploy, and manage agents on AWS Bedrock AgentCore. We identified CVE-2026-12530 , an issue in the install_packages() method of the Code Interpreter client. The method applied an incomplete blocklist to sanitize package name arguments before constructing a 'pip install' shell command executed within the Code Interpreter sandbox. This allowed crafted package name arguments to bypass validation - most critically, pip's '--index-url' flag, which could redirect package resolution to an third-party-controlled PyPI server, and the '-r' flag, which could read and expose arbitrary sandbox files. Impacted versions:  AWS Bedrock AgentCore Python SDK (bedrock-agentcore) versions >= 1.1.3 and Resolution: This issue has been addressed in bedrock-agentcore version 1.6.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you are unable to upgrade immediately, avoid passing any user-supplied or e

Severity from
no source yet

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.