Amazon Bedrock AgentCore Vulnerability
AgentCore's InvokeHarness API had a vulnerability allowing tool-use block injection, fixed by AWS. The underlying open-source Strands code remains vulnerable.
AgentCore's InvokeHarness API had a vulnerability allowing tool-use block injection, fixed by AWS. The underlying open-source Strands code remains vulnerable.
The open-source Strands Python code, which underpins AWS AgentCore, contains a model-skipping path that remains unpatched. AWS documented the behavior instead of…