HIGH 9.0 GitHub
CVE-2026-11393
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
### Summary
The AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. An issue exists where, under certain circumstances, a crafted collaborationInstruction value stored in Bedrock Agent collaborator metadata can break out of a Python triple-quoted string in code generated by the `agentcore add agent --type import` command, resulting in arbitrary code execution when the generated file is loaded or deployed.
### Impact
When a
Affected Products
- npm/@aws/agentcore >= 0.4.0, < 0.14.2
- npm/@aws/agentcore >= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0
- npm/@aws/agentcore >= 1.0.0-preview.1, < 1.0.0-preview.9
References
- https://github.com/advisories/GHSA-m4x6-gwgp-4pm7
- https://github.com/aws/agentcore-cli/security/advisories/GHSA-m4x6-gwgp-4pm7
- https://nvd.nist.gov/vuln/detail/CVE-2026-11393
- https://github.com/aws/agentcore-cli/pull/1329
This high severity vulnerability with a CVSS score of 9.0 was published on 2026-07-29 via GitHub. Affected: npm/@aws/agentcore >= 0.4.0, < 0.14.2, npm/@aws/agentcore >= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0, npm/@aws/agentcore >= 1.0.0-preview.1, < 1.0.0-preview.9.
Risk Timeline
CVE Disclosed2026-07-29 · 5 days ago
Remediation Resources
NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2026-11393Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-52887 | NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE | CRITICAL | 10.0 |
| CVE-2026-53609 | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operat | CRITICAL | 9.1 |
| CVE-2026-69264 | Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into P | CRITICAL | — |
| CVE-2026-70470 | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE | CRITICAL | — |
| CVE-2025-4318 | AWS Amplify Studio UI Component Properties Has an Input Validation Issue | CRITICAL | — |
| CVE-2026-54639 | Style Dictionary - Prototype Pollution in convertTokenData utility function | HIGH | 8.8 |
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.