CVE-2026-11393 - Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import
Amazon Bedrock ยท 2026-08-20
Actions
Technical Details
| Affected Versions | @aws/agentcore >= 0.4.0 AND <= 0.14.1, preview versions >= 0.3.0-preview.7.0 and <= 1.0.0-preview.8 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-11393 |
| Migration Required | Yes |
| Cost Impact | Neutral |
What This Means
For DevOps Teams
Update the AgentCore CLI to version 0.14.2 or 1.0.0-preview.9, remove affected agents, and re-import them to ensure the generated main.py is secure and free from code injection vulnerabilities.
For Platform Teams
Deploy the latest AgentCore CLI version across development and production environments to eliminate the code injection vulnerability and maintain a secure infrastructure.
For Executives
Implement the security patch for AgentCore CLI to mitigate the risk of code injection and protect sensitive data, ensuring compliance and maintaining customer trust.
Source
Related Amazon Bedrock Updates
- Introducing cross-Region inference for OpenAI GPT-5.6 models on Amazon Bedrock (2026-08-20)
- CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() (2026-08-20)
- CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness โ Insufficient Input Validation (2026-08-20)
- CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() (2026-08-20)
- Amazon Bedrock now supports SpaceXAI Grok 4.6 with Cross Region Inferencing (2026-08-19)