On Sept. 28, 2026, BeyondTrust disclosed two vulnerabilities in the Amazon Bedrock AgentCore Python SDK that could let crafted package names run commands in its Code Interpreter sandbox. BeyondTrust researchers also reported retrieving temporary execution-role credentials in a proof-of-concept test involving a custom interpreter with an attached role.
Two AgentCore SDK flaws could allow command execution
The affected component was install_packages(), a helper in the Python SDK’s Code Interpreter client that builds the command used to install packages. An SDK, or software development kit, is a set of tools developers use to build software for a platform.
AWS’s security bulletins identified two CVEs, each with a different affected-version range and fix:
Affected versions and AWS fixes
| CVE | Affected bedrock-agentcore versions | Fixed version |
| CVE-2026-12530 | >=1.1.3 and <1.6.1 | 1.6.1 |
| CVE-2026-16796 | <1.18.1 | 1.18.1 |
How package-name input reached the helper
BeyondTrust said the first flaw involved a newline in a package name slipping past an incomplete character blocklist. Its researchers later found that the replacement validation still accepted pip extras syntax, which could bypass the first fix. Both issues involved how the SDK helper handled package names when constructing an installation command.
When execution-role credentials were at risk
The reported credential retrieval depended on three conditions: attacker-influenced input had to reach install_packages(), the application had to use an affected SDK version, and a custom Code Interpreter had to have an execution role attached. In a proof-of-concept test with that configuration, BeyondTrust researchers retrieved temporary credentials associated with the role from the interpreter’s metadata service.
AWS’s upgrade advice
AWS advised users to upgrade to bedrock-agentcore version 1.18.1 or later and not pass untrusted or model-generated package names to install_packages(). For applications that accept package names dynamically, AWS also recommended validating them against strict PyPI naming rules.