Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRF
Critical9.0CVE-2026-105812 · Published Oct 6, 2026
Bulletin ID: 2026-127-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/06/2026 13:30 PM PDT Description: bedrock-agentcore-starter-toolkit is an AWS-maintained open-source Python package, distributed via GitHub and PyPI, that provides a command-line interface for importing Amazon Bedrock Agents into local development environments. We identified CVE-2026-105812, a code injection issue that could allow arbitrary code execution when a specially crafted agent is imported and subsequently run or deployed, and CVE-2026-106032, an external reference handling issue that could cause unintended network requests or local file access during agent import. Affected versions: >= 0.1.4 and <= 0.3.13 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Oct 7 | Severity: Unrated to Critical |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Severity from
- NVD
- Also known as
- CVE-2026-106032
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 2 | OS command injection in the Studio Space startup script in Amazon SageMaker Distribution | Critical9.0 | No fix yet |
| Oct 2 | Issues in Loom for AWS | Critical10.0 | No fix yet |
| Oct 1 | Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python) | Medium5.3 | No fix yet |
| Oct 1 | Uncontrolled recursion in the Ion reader in Amazon Ion Python | High7.5 | No fix yet |
| Oct 1 | Argument injection in AWS security-agent-mcp-server diff scan | High8.2 | No fix yet |
| Oct 1 | Mount Option Injection in Amazon EFS CSI Driver | Medium6.5 | No fix yet |