CVE-2026-107322 - OS command injection in Amazon Agent Plugins for AWS databases-on-aws
Bulletin ID: 2026-130-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/08/2026 11:30 AM PDT
Description:
Amazon Agent Plugins for AWS is an open source collection of plugins that extends supported AI coding agents with AWS-focused workflows and tool integrations. The databases-on-aws plugin provides database design, development, migration, and operational guidance, including Aurora DSQL helper scripts.
We identified CVE-2026-107322, where an incomplete list of disallowed inputs in databases-on-aws versions before 1.7.1 could allow a remote unauthenticated actor to supply crafted content that an agent ingests. The affected code is not a listening network service; operating-system command execution on the host is possible only if the agent subsequently invokes the local helper with the crafted database command value. Any resulting command runs with the permissions of the process running the helper. This issue does not affect the Aurora DSQL service or bypass database privileges.
Impacted versions: databases-on-aws versions 1.0.0 through 1.7.0
Resolution:
The fix is included in databases-on-aws 1.7.1 and later and became available from the marketplace, which is served from the repository's main branch, on August 26, 2026. We recommend upgrading to the latest version, verifying that the updated plugin is active in every environment where it is used, and ensuring any forked or derivative code incorporates the fix. Customers using a pinned repository revision should use commit 8b13a503746a4ebb0402b936645163224058bde3 or later rather than relying on a 1.7.1 release tag.
Workarounds:
Customers who cannot immediately upgrade should avoid the optional psql connection helper command path and use only manually reviewed SQL, or use the DSQL MCP server provided through the plugin instead of the helper. Running the agent and helper as an unprivileged operating-system user with a dedicated AWS IAM role limited to dsql:DbConnect and a scoped database role, preferably read-only where appropriate, further limits the permissions available to the process. Do not use admin or grant dsql:DbConnectAdmin for routine agent operations. Customers who have reason to believe the helper host was inappropriately accessed should rotate or revoke the AWS credentials accessible to that process and review, revoke, or replace the database roles and IAM-to-database role mappings available to it. These measures reduce potential impact while an upgrade is scheduled; upgrading remains the recommended resolution.
References:
Acknowledgement:
We would like to thank Shay Sakazi (@shaysakazi) for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.