Amazon Agent Plugins for AWS: Command Injection Vulnerability in databases-on-aws
Amazon Agent Plugins for AWS databases-on-aws plugin (versions before 1.7.1) has a command injection vulnerability (CVE-2026-107322) that could let attackers execute OS commands through crafted database inputs. User action required: upgrade to version 1.7.1 or later immediately. The vulnerability only triggers if an agent invokes the local helper with malicious input, running commands with helper process permissions.
source: [aws/security-bulletin]