CVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRF
Bulletin ID: 2026-127-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/06/2026 13:30 PM PDT
Description:
bedrock-agentcore-starter-toolkit is an AWS-maintained open-source Python package, distributed via GitHub and PyPI, that provides a command-line interface for importing Amazon Bedrock Agents into local development environments. We identified CVE-2026-105812, a code injection issue that could allow arbitrary code execution when a specially crafted agent is imported and subsequently run or deployed, and CVE-2026-106032, an external reference handling issue that could cause unintended network requests or local file access during agent import.
Affected versions: >= 0.1.4 and <= 0.3.13
Resolution:
This issue has been addressed in bedrock-agentcore-starter-toolkit version 0.3.14. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Agents imported with an affected version must be re-imported with version 0.3.14 or later and their local and deployed output artifacts replaced.
Workarounds:
bedrock-agentcore-starter-toolkit has been deprecated as of March 27, 2026. Customers who have not yet migrated can avoid unintended disclosure by refraining from running the agentcore create import or agentcore import-agent commands against Bedrock Agents whose data-plane fields may have been modified by other principals in the same account. The recommended long-term action is to migrate to the replacement tooling, AgentCore CLI (@aws/agentcore), which contains the equivalent fix for the same issue class.
References:
Acknowledgement:
We would like to thank Koh Jun Sheng for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.