216.73.217.22

CVE-2026-11393

· Published 08/06/2026 19:16 · Modified 09/06/2026 13:34

Labels: CVE-2026-11393 2026-06-08CVE-2026-11393CWE-94ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
08/06/2026 19:16
Modified
09/06/2026 13:34
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another user in the same AWS account, via a crafted collaborationInstruction stored on a Bedrock Agent collaborator and later processed by that other user during agent import. To remediate this issue, users should upgrade to version 0.14.2.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
agentcore / agentcore cli cpe:2.3:a:agentcore:agentcore_cli:<0.14.2:*:*:*:*:*:*:*
aws / agentcore runtime cpe:2.3:a:aws:agentcore_runtime:*:*:*:*:*:*:*:*

References