AWS published two high-severity advisories in 2026 for argument-injection flaws in install_packages() in the bedrock-agentcore Python SDK’s Code Interpreter client. AWS listed 1.6.1 as the patched version for CVE-2026-12530 and 1.18.1 for CVE-2026-16796. Both advisories describe a risk of command execution in the sandbox if a remote authenticated user can influence the method’s arguments.

Two flaws, two patched versions

An SDK, or software development kit, is a set of tools developers use to build with a platform. AWS’s advisories concern the package-installation method in its Code Interpreter client; each vulnerability has its own affected range and patched release.

VulnerabilityAffected bedrock-agentcore versionsPatched versionSeverityAdvisory published
CVE-2026-12530>= 1.1.3 and < 1.6.11.6.1HighJune 17, 2026
CVE-2026-16796< 1.18.11.18.1HighJuly 23, 2026

How crafted arguments could reach command execution

The flaws share a method, but AWS describes different input-handling failures. For CVE-2026-12530, incomplete filtering let crafted pip options—including --index-url and -r—pass validation. AWS says the issue could redirect package resolution or expose files and environment variables in the sandbox.

For CVE-2026-16796, AWS describes improper handling of argument delimiters in crafted package specifiers. In both advisories, the command-execution risk applies when a remote authenticated user can influence arguments passed to install_packages().

AWS guidance for package inputs

AWS advises developers not to pass untrusted or externally influenced strings directly to install_packages(). For CVE-2026-12530, if an upgrade is not possible, AWS recommends a fixed, hardcoded list of approved package names. For CVE-2026-16796, its guidance is to avoid untrusted or model-generated input and strictly validate dynamic package names and extras; when extras are used, constrain them to comma-separated identifiers.