bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Tuesday, October 6, 2026

AWS Bedrock AgentCore Starter Toolkit: Critical Code Injection and SSRF Vulnerabilities

bedrock-agentcore-starter-toolkit versions 0.1.4 through 0.3.13 have two nasty security issues: CVE-2026-105812 allows arbitrary code execution when importing malicious agents, while CVE-2026-106032 can trigger unwanted network requests or file access. If you're using this AWS Python package, update immediately—user action is required.

source: [aws/security-bulletin]