bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: Lambda security

show all
Thursday, August 20, 2026

QnABot on AWS: Critical Sandbox Bypass Lets Admins Execute Arbitrary Code

QnABot on AWS versions 7.2.4 and earlier have a nasty vulnerability (CVE-2026-7191) where authenticated admins can break out of the expression sandbox using JavaScript prototype manipulation. An attacker with admin access could inject malicious code through the Content Designer, gaining direct access to Lambda environment variables, OpenSearch indices, S3 objects, and DynamoDB tables. If you're running QnABot, update immediately—this one requires your attention.

source: [aws/security-bulletin]