Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
Vulnerability Description
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.
To mitigate this issue, users should upgrade to the patched version 1.18.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
参数注入或修改
Vulnerability Title
Amazon Bedrock AgentCore SDK 命令注入漏洞
Vulnerability Description
AWS Bedrock AgentCore SDK是AWS公司开源的一个用于将本地 AI 智能体零基础设施部署到 AWS 的 SDK,支持多种开源框架,提供运行时、记忆、网关、代码解释器等企业级服务。 Amazon Bedrock AgentCore SDK 1.18.1之前版本存在命令注入漏洞,该漏洞源于install_packages()方法对参数分隔符中和不当,可能允许远程认证用户通过特制的包名参数在Code Interpreter沙箱中执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A