Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK...
UnratedCVE-2026-16796 · Published Jul 23, 2026 · updated Sep 22, 2026
Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796 , an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. Impacted versions: bedrock-agentcore version Resolution: This issue has been addressed in bedrock-agentcore version 1.18.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you are not able to upgrade, do not pass untrusted or model-generated input to install_packages(). Applications that must accept dynamic package names should validate them against strict PyPI naming rules, including constraining any extras group to comma-separated identifiers, before calling the SDK. References: CVE-2026-16796 GHSA-j6g5-3...
Affected versions
Details and references
Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796 , an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. Impacted versions: bedrock-agentcore version Resolution: This issue has been addressed in bedrock-agentcore version 1.18.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you are not able to upgrade, do not pass untrusted or model-generated input to install_packages(). Applications that must accept dynamic package names should validate them against strict PyPI naming rules, including constraining any extras group to comma-separated identifiers, before calling the SDK. References: CVE-2026-16796 GHSA-j6g5-3hh3-pgw8 Acknowledgement: We would like to thank Sergio Garcia and BeyondTrust Phantom Labs for collaborating on this issue through the coordinated issue disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-065-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796 , an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. Impacted versions: bedrock-agentcore version Resolution: This issue has been addressed in bedrock-agentcore version 1.18.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you are not able to upgrade, do not pass untrusted or model-generated input to install_packages(). Applications that must accept dynamic package names should validate them against strict PyPI naming rules, including constraining any extras group to comma-separated identifiers, before calling the SDK. References: CVE-2026-16796 GHSA-j6g5-3hh3-pgw8 Acknowledgement: We would like to thank Sergio Garcia and BeyondTrust Phantom Labs for collaborating on this issue through the coordinated issue disclosure process. Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Allocation of resources without limits in the default aws-smithy-http-server serve() path... | Unrated | No fix yet |
| Jul 23 | AWS API MCP Server Security Policy Bypass via Startup Failure | Unrated | No fix yet |
| Jul 22 | AWS CDK CodeBuild S3 Log Encryption Boolean Inversion | Low3.3 | 2.253.0+2 more |
| Jul 21 | QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls | Medium5.3 | 1.7.6 |
| Jul 21 | Issues with s2n-tls: an open-source implementation of the TLS/SSL protocols | Unrated | No fix yet |
| Jul 21 | Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows... | Unrated | No fix yet |