TWO flaws in Amazon Bedrock AgentCore’s Python SDK could allow attackers to run commands inside the Code Interpreter sandbox and access the AWS credentials attached to affected workloads. The issues targeted the SDK’s Code Interpreter helper used during package installation. The CVEs are CVE-2026-12530 and CVE-2026-16796.
According to BeyondTrust’s technical write-up, the first vulnerability arose when a crafted package name bypassed an incomplete blocklist, enabling shell commands to be executed inside the sandbox and leading to leakage of temporary credentials. AWS issued a fix in version 1.6.1, replacing the blocklist with stricter validation, but BeyondTrust later demonstrated that this initial fix could be bypassed by exploiting the package name.
The second vulnerability, CVE-2026-16796, was reported to affect all SDK versions prior to 1.18.1 and exploited pip’s package extras syntax to sneak commands past the validation. AWS addressed this with a further update in version 1.18.1. In practical terms, credential exposure required attacker-influenced input reaching install_packages(), a vulnerable SDK version, and a custom Code Interpreter with an execution role attached.
Once code executed in the sandbox, the impact depended on the execution role’s permissions and could resemble legitimate activity in AWS logs. AWS assigns CVSS scores of 7.3 (CVSS 3.1) and 8.4 (CVSS 4.0) to the flaws, and customers are urged to upgrade to 1.18.1 or later and to avoid passing untrusted or model-generated package names to the helper, with a recommendation to tightly scope IAM permissions and monitor Code Interpreter activity.