PT-2026-60522 · Aws · Bedrock Agentcore Python Sdk
CVE-2026-15737
·
Published
2026-07-16
·
Updated
2026-07-16
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AWS Bedrock AgentCore Python SDK versions 1.4.8 through 1.5.0
Description
OpenTelemetry instrumentation in the SDK causes unintended logging of sensitive user content. The library writes raw user prompts and complete agent responses into OpenTelemetry span attributes during every invocation without filtering or masking. These spans are sent to the
aws/spans CloudWatch log group, potentially allowing a local authenticated user with log read access to view sensitive data.Recommendations
Upgrade to version 1.5.1 or later.
Review and purge sensitive content from
aws/spans CloudWatch log groups.Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bedrock Agentcore Python Sdk