Executive brief
The Bedrock AgentCore Starter Toolkit, a tool used to build and deploy AI agents on AWS, contains a security flaw in how it verifies data storage locations. An attacker could potentially inject malicious code during the software build process, leading to unauthorized code execution within the agent's runtime environment. This could allow an attacker to compromise the AI agent's operations or access sensitive data processed by the toolkit.
Technical details
The vulnerability is caused by improper S3 bucket ownership verification within the Bedrock AgentCore Starter Toolkit's build process. Because the toolkit fails to confirm that the S3 bucket used during the build is owned by the expected account, a remote attacker could potentially supply malicious artifacts. This supply-chain style attack allows for code injection that persists into the AgentCore Runtime environment. The issue specifically impacts builds performed after September 24, 2025, using toolkit versions prior to v0.1.13. Users are advised to upgrade to version v0.1.13 or later to remediate the flaw.
Affected products
- AWS Bedrock AgentCore Starter Toolkit < v0.1.13
Timeline
- 2026-03-16: advisory: AWS published security bulletin 2026-008-AWS
- 2026-03-16: disclosed: CVE-2026-4269 was publicly disclosed