AWS published two high-severity advisories in 2026 for argument-injection flaws in install_packages() in the bedrock-agentcore Python SDK’s Code Interpreter client. AWS listed 1.6.1 as the patched version for CVE-2026-12530 and 1.18.1 for CVE-2026-16796. Both advisories describe a risk of command execution in the sandbox if a remote authenticated user can influence the method’s arguments.
Two flaws, two patched versions
An SDK, or software development kit, is a set of tools developers use to build with a platform. AWS’s advisories concern the package-installation method in its Code Interpreter client; each vulnerability has its own affected range and patched release.
| Vulnerability | Affected bedrock-agentcore versions | Patched version | Severity | Advisory published |
| CVE-2026-12530 | >= 1.1.3 and < 1.6.1 | 1.6.1 | High | June 17, 2026 |
| CVE-2026-16796 | < 1.18.1 | 1.18.1 | High | July 23, 2026 |
How crafted arguments could reach command execution
The flaws share a method, but AWS describes different input-handling failures. For CVE-2026-12530, incomplete filtering let crafted pip options—including --index-url and -r—pass validation. AWS says the issue could redirect package resolution or expose files and environment variables in the sandbox.
For CVE-2026-16796, AWS describes improper handling of argument delimiters in crafted package specifiers. In both advisories, the command-execution risk applies when a remote authenticated user can influence arguments passed to install_packages().
AWS guidance for package inputs
AWS advises developers not to pass untrusted or externally influenced strings directly to install_packages(). For CVE-2026-12530, if an upgrade is not possible, AWS recommends a fixed, hardcoded list of approved package names. For CVE-2026-16796, its guidance is to avoid untrusted or model-generated input and strictly validate dynamic package names and extras; when extras are used, constrain them to comma-separated identifiers.