bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-11393

show all
Thursday, August 20, 2026

AWS AgentCore CLI Code Injection Vulnerability Requires Immediate Update

AWS AgentCore CLI (@aws/agentcore) versions 0.4.0–0.14.1 have a code injection flaw (CVE-2026-11393) where improper triple-quote escaping in Python code generation lets authenticated users inject arbitrary code via the collaborationInstruction field. If you're using affected versions, update immediately—especially if you run agentcore dev or agentcore deploy/invoke commands. The vulnerability requires bedrock:AssociateAgentCollaborator IAM permissions to exploit, but injected code runs with your context credentials.

source: [aws/security-bulletin]