2026-065-AWSHigh
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT
Description:
The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796, an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.
Impacted versions: bedrock-agentcore version
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.