bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, October 8, 2026

Amazon Agent Plugins for AWS: Command Injection Vulnerability in databases-on-aws

Amazon Agent Plugins for AWS databases-on-aws plugin (versions before 1.7.1) has a command injection vulnerability (CVE-2026-107322) that could let attackers execute OS commands through crafted database inputs. User action required: upgrade to version 1.7.1 or later immediately. The vulnerability only triggers if an agent invokes the local helper with malicious input, running commands with helper process permissions.

source: [aws/security-bulletin]