CVE-2026-12530
Received Received - Intake
Improper Argument Delimiter Handling in AWS Bedrock AgentCore SDK

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: AMZN

Description
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to version 1.6.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-18
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
aws bedrock_agentcore_python_sdk From 1.1.3 (inc) to 1.6.1 (exc)
aws bedrock_agentcore_python_sdk 1.6.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

The vulnerability can allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox. This could lead to unauthorized actions being performed, potentially compromising the integrity and security of the system running the vulnerable SDK.

Mitigation Strategies

To mitigate this issue, users should upgrade the AWS Bedrock AgentCore Python SDK to version 1.6.1.

Executive Summary

This vulnerability involves improper neutralization of argument delimiters in the install_packages() method of the AWS Bedrock AgentCore Python SDK versions 1.1.3 up to but not including 1.6.1. This flaw might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox by crafting malicious package name arguments.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12530. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart