PT-2026-47432 · Aws · Agentcore Cli

CVE-2026-11393

·

Published

2026-06-08

·

Updated

2026-07-29

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AgentCore CLI versions prior to 0.14.2
Description Improper neutralization of triple-quote characters during Python code generation allows an authenticated remote actor to execute arbitrary code. This occurs when a crafted collaborationInstruction stored on a Bedrock Agent collaborator is processed by another user during agent import. The execution can take place on the AWS AgentCore Runtime under the imported agent's IAM execution role or within the local environment of another user in the same AWS account.
Recommendations Upgrade to version 0.14.2.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11393
GHSA-M4X6-GWGP-4PM7

Affected Products

Agentcore Cli