CVE-2026-18830: AWS Bedrock AgentCore Tool-Use Injection
Insufficient input validation in Amazon Bedrock AgentCore's InvokeHarness API allows authenticated remote users to inject tool-use blocks that bypass model invocation, leading…
Insufficient input validation in Amazon Bedrock AgentCore's InvokeHarness API allows authenticated remote users to inject tool-use blocks that bypass model invocation, leading…
AgentCore's InvokeHarness API had a vulnerability allowing tool-use block injection, fixed by AWS. The underlying open-source Strands code remains vulnerable.
The open-source Strands Python code, which underpins AWS AgentCore, contains a model-skipping path that remains unpatched. AWS documented the behavior instead of…
AWS patched a critical vulnerability in Amazon Bedrock AgentCore's InvokeHarness API, but the open-source Strands code remains vulnerable. The company documented the…