CVE 9 CRITICAL

Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent import_CVE-2026-11393

9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Description

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another user in the same AWS account, via a crafted collaborationInstruction stored on a Bedrock Agent collaborator and later processed by that other user during agent import.



To remediate this issue, users should upgrade to version 0.14.2.

AI Analysis

Code injection vulnerability in AgentCore CLI due to improper neutralization of triple-quote characters, allowing remote code execution

Basic Information

ID CVE-2026-11393
Source AMZN
Published Jun 8, 2026 at 18:38
Modified Jun 8, 2026 at 18:49

Affected Product

Vendor AWS
Product AgentCore CLI
Version 0.4.0
Affected Versions AWS AgentCore CLI 0.4.0
AWS AgentCore CLI 0.3.0-preview.7.0

CWE Classification

AI Assessment

AI Score 9 / 10
AI Severity Critical
Vendor Amazon Web Services (AWS)
Product AgentCore CLI
Version 0.4.0, 0.3.0-preview.7.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.