CVE-2026-16796
HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
Title source: cnaDescription
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to the patched version 1.18.1.
References (3)
Core 3
Core References
Patch release-notes
patch
https://pypi.org/project/bedrock-agentcore/1.18.1/
Vendor Advisory vendor-advisory
https://aws.amazon.com/security/security-bulletins/2026-065-aws/
Release Notes release-notes
https://github.com/aws/bedrock-agentcore-sdk-python/security/advisories/GHSA-j6g5-3hh3-pgw8
Scores
CVSS v3
7.3
EPSS
0.0033
EPSS Percentile
25.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-88
Status
published
Products (2)
AWS/bedrock-agentcore 1.18.1
< 1.18.1
pypi/bedrock-agentcore
0 - 1.18.1PyPI
Published
Jul 23, 2026
Tracked Since
Jul 24, 2026