VYPR
High severity7.1NVD Advisory· Published May 22, 2026· Updated Jul 23, 2026

CVE-2026-9291

CVE-2026-9291

Description

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results.

We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
amazon-braket-sdkPyPI
>= 1.10.0, < 1.117.01.117.0

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.