{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-11393/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9,"id":"CVE-2026-11393"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AgentCore CLI"],"_cs_severities":["high"],"_cs_tags":["code-injection","supply-chain","amazon-bedrock","cve-2026-11393"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eCVE-2026-11393 affects the Amazon AgentCore CLI (versions 0.4.0 through 0.14.1 and preview versions 0.3.0-preview.7.0 through 1.0.0-preview.8). The vulnerability exists within the 'agentcore add agent --type import' command, which improperly handles the 'collaborationInstruction' field fetched from Bedrock agent metadata. This field is interpolated into a triple-quoted string within a generated Python file (main.py). By crafting a metadata value containing triple double-quotes, an attacker can break the string boundary and inject arbitrary Python code. This vulnerability is significant because the injected code executes in the developer's local environment during development and within the AWS AgentCore Runtime environment during agent invocation, potentially compromising the AWS execution role.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker with 'bedrock:AssociateAgentCollaborator' permissions associates a malicious collaborator agent with a target supervisor agent.\u003c/li\u003e\n\u003cli\u003eThe attacker sets the 'collaborationInstruction' field of the collaborator metadata to a payload containing triple double-quotes followed by arbitrary Python code.\u003c/li\u003e\n\u003cli\u003eA developer or automated process executes 'agentcore add agent --type import' to ingest the supervisor agent configuration.\u003c/li\u003e\n\u003cli\u003eThe AgentCore CLI fetches the metadata from the Bedrock API and injects the payload directly into the 'main.py' file.\u003c/li\u003e\n\u003cli\u003eThe developer runs 'agentcore dev' on their local machine, triggering the execution of the injected Python code under their current local AWS credentials.\u003c/li\u003e\n\u003cli\u003eThe developer executes 'agentcore deploy' and subsequently triggers 'agentcore invoke', causing the injected code to run in the cloud environment under the agent's IAM execution role.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for arbitrary code execution on both local developer workstations and in the AWS runtime environment where the agent is deployed. An attacker could leverage this to steal local developer credentials or abuse the IAM execution role of the deployed Bedrock agent to perform unauthorized actions within the victim's AWS account. Any agent imported or redeployed using vulnerable CLI versions remains susceptible until the code is regenerated with a patched CLI version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the AgentCore CLI to version 0.14.2 or 1.0.0-preview.9 immediately to prevent new occurrences of the injection.\u003c/li\u003e\n\u003cli\u003eFor all previously imported agents, developers must remove the agent from the project, re-run 'agentcore add agent --type import' using the patched CLI to regenerate a clean 'main.py', and redeploy the agent to AWS.\u003c/li\u003e\n\u003cli\u003eManually audit the 'main.py' files of existing imported agents for triple double-quote sequences if immediate regeneration is not possible.\u003c/li\u003e\n\u003cli\u003eRestrict 'bedrock:AssociateAgentCollaborator' IAM permissions to authorized users to mitigate the likelihood of malicious metadata injection.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-29T16:11:04Z","date_published":"2026-07-29T16:11:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-agentcore-code-injection/","summary":"The AgentCore CLI is vulnerable to arbitrary code execution due to improper escaping of metadata when importing Amazon Bedrock agents, allowing attackers to inject malicious Python code into generated files.","title":"AgentCore CLI Code Injection Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-agentcore-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-11393","version":"https://jsonfeed.org/version/1.1"}