Security Advisory Desk
unratedQCS priority 76/100Amazon Web Services

CVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRF

AWS discovered two security problems in their Bedrock AgentCore Starter Toolkit, a Python package for working with Amazon Bedrock Agents locally. One problem (CVE-2026-105812) allows attackers to run malicious code if they import a specially crafted agent and then run or deploy it. The other problem (CVE-2026-106032) involves improper handling of external references that could cause unexpected network requests or unauthorized file access when importing an agent. AWS advises updating to version 0.3.14 or later and re-importing agents to apply fixes. The toolkit has been deprecated, so they recommend switching to the new AgentCore CLI tool for future work.

QCS published 7/10/2026, 5:20:19 am ISTVendor disclosure 7/10/2026, 2:11:24 am ISTVerified 7/10/2026, 5:20:19 am ISTRevision 1

In plain language

What this advisory means

AWS discovered two security problems in their Bedrock AgentCore Starter Toolkit, a Python package for working with Amazon Bedrock Agents locally. One problem (CVE-2026-105812) allows attackers to run malicious code if they import a specially crafted agent and then run or deploy it. The other problem (CVE-2026-106032) involves improper handling of external references that could cause unexpected network requests or unauthorized file access when importing an agent. AWS advises updating to version 0.3.14 or later and re-importing agents to apply fixes. The toolkit has been deprecated, so they recommend switching to the new AgentCore CLI tool for future work.

Technical explanation

How the issue affects the environment

The bedrock-agentcore-starter-toolkit package versions 0.1.4 and above contain two vulnerabilities. CVE-2026-105812 is a code injection flaw where importing a maliciously crafted Bedrock Agent can lead to arbitrary code execution upon running or deploying the agent. CVE-2026-106032 is an external reference handling weakness that can trigger unintended network calls or local file access during agent import. These issues arise during the import process of Bedrock Agents in local development environments. AWS resolved these vulnerabilities in version 0.3.14 by applying fixes that prevent code injection and secure external resource handling. Agents imported with affected versions must be re-imported using the fixed version to replace potentially unsafe artifacts. The original toolkit was deprecated in March 2026, and AWS recommends migrating to the AgentCore CLI, which includes equivalent security improvements.

Operational impact

Why teams should care

Organizations using the vulnerable versions of the Bedrock AgentCore Starter Toolkit risk unauthorized code execution and potential data exposure via unintended network requests or file access. This can compromise local development environments and any deployments derived from them, leading to operational disruptions, data breaches, or system compromise. Immediate remediation and migration to supported tooling are essential to maintain security and trust in AI application development workflows.

Immediate action

Upgrade the bedrock-agentcore-starter-toolkit package to version 0.3.14 or later. Re-import all Bedrock Agents previously imported with affected versions to replace unsafe output artifacts locally and in deployed environments. Migrate to the replacement AgentCore CLI (@aws/agentcore) to continue secure development with equivalent fixes. Review and patch any forked or derivative code accordingly.

Affected and fixed releases

Affected versions>= 0.1.4
Fixed versions0.3.14

Temporary risk reduction

Since the bedrock-agentcore-starter-toolkit was deprecated on March 27, 2026, users who have not migrated should avoid running the agentcore create import or agentcore import-agent commands on Bedrock Agents whose data-plane fields might have been modified by other principals within the same account to prevent unintended code execution or data leaks.

Evidence and validation checklist

  • AWS Security Bulletin ID 2026-127-AWS published 2026-10-06 13:30 PDT stating the vulnerabilities and fixes.
  • Acknowledgement of Koh Jun Sheng for coordinated vulnerability disclosure.
  • Official recommendation to upgrade to version 0.3.14 and migrate to AgentCore CLI.
  • Detailed description of the technical vulnerabilities including code injection and SSRF issues during agent import.

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source