GHSA-j6g5-3hh3-pgw8
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
Quick fix
GHSA-j6g5-3hh3-pgw8 — bedrock-agentcore: upgrade to the fixed version with the command below.
pip install --upgrade 'bedrock-agentcore>=1.18.1' Details
### Summary
The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. An issue exists where, under certain circumstances, improper neutralization of argument delimiters in the install_packages() method allows a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.
### Impact Insufficient input validation in install_packages() allows specially crafted package specifiers to bypass validation and achieve arbitrary command execution within the sandbox. A remote authenticated user who can influence the arguments to install_packages() can execute arbitrary commands within the Code Interpreter sandbox environment.
### Impacted Versions < 1.18.1
### Patches This issue has been addressed in bedrock-agentcore version 1.18.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
### Workarounds If you are not able to upgrade, do not pass untrusted or model-generated input to install_packages(). Applications that must accept dynamic package names should validate them against strict PyPI naming rules -- including constraining any extras group to comma-separated identifiers -- before calling the SDK.
### References If you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.
### Acknowledgement
AWS would like to thank Sergio Garcia (@MrCloudSec) for collaborating on this issue through the coordinated issue disclosure process.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 1.18.1 pip install --upgrade 'bedrock-agentcore>=1.18.1' References
- https://github.com/aws/bedrock-agentcore-sdk-python/security/advisories/GHSA-j6g5-3hh3-pgw8 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-16796 [ADVISORY]
- https://github.com/aws/bedrock-agentcore-sdk-python/pull/581 [WEB]
- https://github.com/aws/bedrock-agentcore-sdk-python/commit/3c4b4ee6b8730e6313a82c743ac37dbcc1c21cdb [WEB]
- https://aws.amazon.com/security/security-bulletins/2026-065-aws [WEB]
- https://github.com/aws/bedrock-agentcore-sdk-python [PACKAGE]
- https://pypi.org/project/bedrock-agentcore/1.18.1 [WEB]