HIGH 9.0 GitHub

CVE-2026-11393

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

### Summary The AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. An issue exists where, under certain circumstances, a crafted collaborationInstruction value stored in Bedrock Agent collaborator metadata can break out of a Python triple-quoted string in code generated by the `agentcore add agent --type import` command, resulting in arbitrary code execution when the generated file is loaded or deployed. ### Impact When a

Affected Products

References

Published: 2026-07-29 · Source: GitHub · Feed updated: 2026-08-04
This high severity vulnerability with a CVSS score of 9.0 was published on 2026-07-29 via GitHub. Affected: npm/@aws/agentcore >= 0.4.0, < 0.14.2, npm/@aws/agentcore >= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0, npm/@aws/agentcore >= 1.0.0-preview.1, < 1.0.0-preview.9.

Risk Timeline

CVE Disclosed2026-07-29 · 5 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-52887NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCECRITICAL10.0
CVE-2026-53609Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operatCRITICAL9.1
CVE-2026-69264Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into PCRITICAL
CVE-2026-70470Flowise: Pyodide validator Unicode homoglyph bypass leads to RCECRITICAL
CVE-2025-4318AWS Amplify Studio UI Component Properties Has an Input Validation IssueCRITICAL
CVE-2026-54639Style Dictionary - Prototype Pollution in convertTokenData utility functionHIGH8.8
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.