AgentenCode News · Source-firstPrimary source checked · October 7, 2026

AWS patches AgentCore toolkit security flaws

AWS fixes code-injection and SSRF issues in the AgentCore Starter Toolkit. Versions 0.1.4 through 0.3.13 are affected; version 0.3.14 contains the fix.

Direct answer

AWS fixed two vulnerabilities in the Bedrock AgentCore Starter Toolkit. Version 0.3.14 addresses code injection and unsafe external-reference handling that could trigger network requests or local file access.

Before

Versions 0.1.4 through 0.3.13 of bedrock-agentcore-starter-toolkit were affected by two import-related vulnerabilities, according to AWS.

Now

AWS fixed both issues in version 0.3.14 and recommends upgrading to the latest toolkit release.

AWS published a security bulletin for bedrock-agentcore-starter-toolkit on October 6, 2026. According to AWS, versions 0.1.4 through 0.3.13 are affected. The bulletin lists two CVEs related to importing agent code.

CVE-2026-105812 is a code-injection issue that could allow arbitrary code execution when a specially crafted agent is imported and then run or deployed. CVE-2026-106032 concerns external-reference handling and can cause unintended network requests or local file access.

AWS says both issues are fixed in starter-toolkit version 0.3.14 and recommends upgrading to the latest version. Forked or derivative implementations should incorporate the same fixes.

Scope matters: the bulletin covers the AWS-maintained open-source Python package bedrock-agentcore-starter-toolkit and its import workflow. It does not state that the managed AgentCore service itself has the same vulnerabilities. AgentenCode therefore records this as a security-relevant tooling change in the AgentCore ecosystem.

For teams importing agents from existing Bedrock environments or using the toolkit in CI/CD, the local toolkit version becomes a concrete verification point. Imported agent definitions should also be treated like other untrusted code, with network and file-system permissions constrained during import and validation.

Primary source

Sources behind this update

AgentenCode publishes product changes only after source-first review. The original provider source remains authoritative for current details.

The agent profile, trust evidence and history separate documented properties from Unknown.

Full context in the evidence profile.

The profile, trust evidence and history separate documented properties from Unknown.

Open Amazon Bedrock AgentCore →