AWS Bedrock AgentCore Starter Toolkit: Critical Code Injection and SSRF Vulnerabilities
bedrock-agentcore-starter-toolkit versions 0.1.4 through 0.3.13 have two nasty security issues: CVE-2026-105812 allows arbitrary code execution when importing malicious agents, while CVE-2026-106032 can trigger unwanted network requests or file access. If you're using this AWS Python package, update immediately—user action is required.
source: [aws/security-bulletin]