Security researchers have uncovered a class of vulnerabilities in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel that allow attackers…
Agent InfrastructureAI SecurityAmazon Bedrock AgentCoreAmazon Web Services
Insufficient input validation in Amazon Bedrock AgentCore's InvokeHarness API allows authenticated remote users to inject tool-use blocks that bypass model invocation, leading…
AgentCore's InvokeHarness API had a vulnerability allowing tool-use block injection, fixed by AWS. The underlying open-source Strands code remains vulnerable.