Overview
A critical code-injection vulnerability has been disclosed in the Amazon Bedrock AgentCore Starter Toolkit, the Python CLI toolkit AWS customers use to migrate existing Bedrock Agents into LangChain, LangGraph, or Strands frameworks. Tracked as CVE-2026-105812 with a CVSS 3.1 score of 9.0 (Critical), the flaw sits in the toolkit's agent-import functionality: configuration values pulled in during an import are written directly into generated Python source code without safe literal encoding, giving an authenticated attacker a path to arbitrary code execution when that generated code is later run or deployed.
The issue was published on October 6, 2026, and AWS has shipped a fix in version 0.3.14, available now on PyPI.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105812 |
| Severity | Critical (CVSS 3.1: 9.0) |
| CVSS 4.0 Score | 8.8 (High) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
| CWE | CWE-94 — Improper Control of Generation of Code |
| Attack Vector | Network |
| Privileges Required | Low (authenticated, same-account actor) |
| User Interaction | Required |
| Scope | Changed |
| Affected Versions | 0.1.4 through 0.3.13 |
| Fixed Version | 0.3.14 |
How It Works
The toolkit's Import-Agent feature is designed to make migrating an existing Amazon Bedrock Agent into a LangChain/LangGraph or Strands project painless — it reads the agent's configuration and generates the Python project scaffolding needed to run or deploy it under the new framework. The vulnerability exists because configuration values collected during that import are interpolated straight into the generated .py source files without safe literal encoding.
Because the values are embedded as raw text rather than properly escaped Python literals, a configuration value crafted to break out of its intended string or expression context can inject arbitrary code into the generated script. That code executes whenever a user subsequently imports, runs, or deploys the resulting Bedrock Agent project — turning what looks like ordinary agent configuration into a remote code execution primitive, provided the attacker can get malicious configuration into an agent definition within the same AWS account.
Impact Assessment
Who Is At Risk
Any team that has used the bedrock-agentcore-starter-toolkit CLI (versions 0.1.4–0.3.13) to import a Bedrock Agent is potentially exposed, including environments where:
- Multiple users or service roles within the same AWS account can define or modify Bedrock Agent configurations
- Imported agent projects are later built, tested, or deployed by a different (often higher-privileged) user than the one who configured the agent
- CI/CD pipelines automatically run or package agents generated by the toolkit
Potential Attack Chain
- Same-Account Access — An authenticated actor with permission to configure or import a Bedrock Agent in the target AWS account crafts a malicious configuration value
- Code Generation — A victim runs the Import-Agent command against that configuration, and the toolkit writes the attacker's payload directly into the generated Python source without escaping it
- Execution Trigger — The victim (or an automated pipeline) imports, runs, or deploys the generated project, executing the injected code with whatever privileges that process holds
- Impact — Full compromise of confidentiality, integrity, and availability (CVSS
C:H/I:H/A:H) within the scope of the executing environment
The "Scope: Changed" component of the CVSS vector is notable here: the vulnerable component (the import CLI) and the impacted component (whatever runs the generated agent — potentially a CI runner, a developer workstation, or a deployed Bedrock environment) are different, so the blast radius can extend well beyond the toolkit itself.
Mitigation
Immediate Actions
- Upgrade to version 0.3.14 or later via PyPI:
pip install --upgrade bedrock-agentcore-starter-toolkit - Re-import affected agents. AWS's advisory stresses that upgrading the toolkit alone is not sufficient — any agent project that was previously generated using an affected version (0.1.4–0.3.13) must be re-imported with the patched toolkit and its generated artifacts replaced. Simply upgrading the CLI does not retroactively sanitize code that was already generated.
- Audit existing generated projects for unexpected code in configuration-derived sections of the generated Python source before trusting or re-running them.
Detection Opportunities
- Review AWS CloudTrail and account activity for Bedrock Agent configuration changes made by unexpected or lower-trust principals shortly before an import, run, or deploy action
- Inspect generated agent projects for anomalous Python constructs embedded in what should be plain configuration literals (string concatenation, unexpected function calls,
exec/eval-style patterns)
Defence-in-Depth
- Apply least-privilege IAM policies so that only trusted principals can create or modify Bedrock Agent configurations that will later be imported by higher-privileged users or pipelines
- Treat generated code from any agent-migration tooling as untrusted input until reviewed, especially in shared or multi-tenant AWS accounts
- Pin and track the toolkit version used in CI/CD pipelines so patched releases are picked up promptly rather than drifting on an old, vulnerable version
Discovery & Disclosure
The vulnerability was reported through AWS's Vulnerability Disclosure Program. AWS published a corresponding security bulletin and patched the issue in the same release that also fixed a related server-side request forgery flaw (CVE-2026-106032) in the toolkit's OpenAPI schema processing during agent import. As of publication, CVE-2026-105812 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and its EPSS score remains low, but given the toolkit's role in AI agent supply chains, organizations using it should prioritize patching and re-importing affected agents rather than waiting for confirmed in-the-wild exploitation.