VYPR

bedrock-agentcore

by AWS

Source repositories

CVEs (4)

  • CVE-2026-18830HigAug 4, 2026
    risk 0.53cvss 8.1epss 0.01

    Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer…

  • CVE-2026-16796HigJul 23, 2026
    risk 0.41cvss 7.3epss 0.01

    Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To…

  • CVE-2026-12530HigJun 17, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name…

  • CVE-2026-15737MedJul 16, 2026
    risk 0.00cvss 5.7epss 0.00

    AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK…