HIGH 8.8 NVD

CVE-2026-105812

Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated sam

Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated Python source without safe literal encoding. To remediate this issue, users should upgrade to version 0.3.14. Because this issue persists into generated source, upgrading alone is not sufficient: agents imported with an affected version must be re-imported with version 0.3.14 or later and their local and deployed output artifacts replaced.

References

Published: 2026-10-06 · Source: NVD · Feed updated: 2026-10-06
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.