在 Amazon Bedrock AgentCore Starter Toolkit 0.3.14 之前的版本中,代理导入功能存在代码生成控制不当的问题。该漏洞可能允许经过认证且属于同一账户的攻击者,通过导入并运行或部署 Amazon Bedrock Agent,在生成的 Python 源代码中嵌入精心构造的配置值(未进行安全字面量编码),从而执行任意代码。 要解决此问题,用户应将系统升级至版本 0.3.14。由于漏洞影响会延续到生成的源代码中,仅升级软件版本是不够的:必须使用版本 0.3.14 或更高版本重新导入
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aws | bedrock-agentcore-starter-toolkit | 0.1.4 ~ 0.3.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105811 | 6.5 MEDIUM | Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sa |
| CVE-2026-106032 | 5.7 MEDIUM | Server-side request forgery and local file read via unrestricted external OpenAPI referenc |
No comments yet