A now-patched vulnerability in AWS Bedrock’s AgentCore could allow a single prompt to a public-facing AI chatbot to seize control of an entire AWS account’s AgentCore deployment. Researchers from Zenity Labs demonstrated that agents deployed via Bedrock AgentCore can reach the instance metadata service (IMDS), which stores sensitive data such as temporary credentials, instance IDs and configurations.
By issuing a prompt to a chatbot, an attacker could gain control over the targeted agent and then broaden that access to other agents within the same AWS account and region.
The team found that each AgentCore agent runs inside a Firecracker microVM, lacking adequate network isolation, enabling the attacker to leverage IMDS for temporary credentials. They also discovered that the default AgentCore role granted broad permissions across all AgentCore resources in the entire region, permitting the attacker to invoke other agents, read sessions and access Secrets Manager data.
AWS has since patched the flaw: new agents on AgentCore now use IMDSv2 authentication, and the default role has been tightened to limit cross-agent actions and access to secrets. Zenity reported no confirmed exploitation in the wild prior to the fix, but warns that the underlying IMDS weakness and agent-wide privileges could enable a substantial blast radius if left unaddressed.
The researchers emphasise restricting privileges to the agent’s specific role and continue investigating whether similar issues exist on other cloud platforms.