{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aws-agentcore-harness/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS AgentCore Harness"],"_cs_severities":["high"],"_cs_tags":["agentic-ai","cloud-security","exfiltration","prompt-injection"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eUnit 42 researchers identified a significant security risk in AWS AgentCore Harness resulting from its default configuration. The harness provides a managed runtime for AI agents, which by default enables a 'shell' tool with root privileges within the execution container. This tool is designed to allow agents to perform autonomous tasks such as file manipulation and command execution. However, because this tool is enabled without explicit restriction, it creates a high-impact attack surface.\u003c/p\u003e\n\u003cp\u003eAttackers who successfully perform prompt injection against an agent can coerce the model into utilizing this shell tool to execute arbitrary commands. Because the shell runs as root within the harness's memory space, it can access sensitive data, specifically plaintext credentials managed by AWS AgentCore Identity that have been resolved for downstream integration use. This allows for the exfiltration of credentials used to authenticate agents with external services, effectively bypassing the intended security boundaries of the AgentCore Identity vault at runtime.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to gain root access to the agent's container environment and exfiltrate credentials used to authenticate against downstream services and MCP servers. This impacts organizations relying on AgentCore Harness in production by potentially exposing sensitive internal systems to unauthorized access if the agent's underlying service account permissions are overly broad.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following remediation steps for all AWS AgentCore Harness deployments:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eScope the 'allowedTools' parameter in the harness configuration to explicitly restrict access to only the tools necessary for the agent's intended function; specifically, disable the 'shell' and 'file_operations' tools unless strictly required.\u003c/li\u003e\n\u003cli\u003eImplement the principle of least privilege for Identity vault service accounts by limiting their access exclusively to the downstream integrations they are required to support.\u003c/li\u003e\n\u003cli\u003eConfigure egress traffic filtering for all harness containers to block unauthorized connections to external command-and-control infrastructure.\u003c/li\u003e\n\u003cli\u003eReview all current AgentCore Harness sessions to ensure that default tool capabilities are restricted, as the 'shell' tool is enabled out-of-the-box.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T13:04:47Z","date_published":"2026-09-18T13:04:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-agentcore-harness-vulnerability/","summary":"Default configurations in AWS AgentCore Harness enable a root-privileged shell tool that, when combined with prompt injection, allows attackers to exfiltrate plaintext credentials from the agent runtime.","title":"Credential Exfiltration in AWS AgentCore Harness via Default Shell Tool","url":"https://feed.craftedsignal.io/briefs/2026-09-agentcore-harness-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - AWS AgentCore Harness","version":"https://jsonfeed.org/version/1.1"}