Junglewise Threat Intelligence

CVE-2026-4269: AWS Bedrock AgentCore Starter Toolkit code injection via S3 ownership bypass

CVE-2026-4269 · Severity: high · CVSS 7.5 · Published 2026-03-16

Technologies: Amazon AWS. Vendors: PyPI, Amazon, AWS.

Executive brief

The Bedrock AgentCore Starter Toolkit, a tool used to build and deploy AI agents on AWS, contains a security flaw in how it verifies data storage locations. An attacker could potentially inject malicious code during the software build process, leading to unauthorized code execution within the agent's runtime environment. This could allow an attacker to compromise the AI agent's operations or access sensitive data processed by the toolkit.

Technical details

The vulnerability is caused by improper S3 bucket ownership verification within the Bedrock AgentCore Starter Toolkit's build process. Because the toolkit fails to confirm that the S3 bucket used during the build is owned by the expected account, a remote attacker could potentially supply malicious artifacts. This supply-chain style attack allows for code injection that persists into the AgentCore Runtime environment. The issue specifically impacts builds performed after September 24, 2025, using toolkit versions prior to v0.1.13. Users are advised to upgrade to version v0.1.13 or later to remediate the flaw.

Affected products

  • AWS Bedrock AgentCore Starter Toolkit < v0.1.13

Timeline

  • 2026-03-16: advisory: AWS published security bulletin 2026-008-AWS
  • 2026-03-16: disclosed: CVE-2026-4269 was publicly disclosed

References

Related threats