CyberSecurityBoardThreat Intel · CVEs · Products

Tag: InvokeHarness

Cyber Products

Amazon Bedrock AgentCore Vulnerability

AgentCore's InvokeHarness API had a vulnerability allowing tool-use block injection, fixed by AWS. The underlying open-source Strands code remains vulnerable.

AgentCore Amazon Bedrock AgentCore AWS CVE-2026-18830
August 6, 2026