AWS AgentCore CLI Code Injection Vulnerability Requires Immediate Update
AWS AgentCore CLI (@aws/agentcore) versions 0.4.0–0.14.1 have a code injection flaw (CVE-2026-11393) where improper triple-quote escaping in Python code generation lets authenticated users inject arbitrary code via the collaborationInstruction field. If you're using affected versions, update immediately—especially if you run agentcore dev or agentcore deploy/invoke commands. The vulnerability requires bedrock:AssociateAgentCollaborator IAM permissions to exploit, but injected code runs with your context credentials.
source: [aws/security-bulletin]