Back to Intelligence

Amazon Bedrock AgentCore SDK Flaws: Defending AI Sandboxes From Command Execution and AWS Credential Theft

SA
Security Arsenal Team
September 29, 2026
11 min read

A recent report describes security flaws in the Amazon Bedrock AgentCore SDK that could allow an attacker who influences an AI agent workflow to execute commands inside an AI sandbox and, from there, reach AWS credentials available to that runtime. The source item does not provide a public CVE identifier, CVSS score, or confirmed CISA KEV listing, so defenders should treat this as an active cloud application security risk rather than a numbered patch event. The defensive priority is straightforward: assume agent-executed code can be turned into command execution, assume any sandbox identity can be probed for cloud credentials, and remove easy paths to the instance metadata service, environment variables, temporary session tokens, and over-permissive task or instance roles.

This matters most for organizations deploying Bedrock agents, AgentCore runtimes, tool-using LLM workflows, code-interpreter style sandboxes, or MCP-connected automation on AWS compute such as EC2, ECS, EKS, Lambda-adjacent services, or developer workstations running the SDK locally. The blast radius is not limited to the sandbox. If the runtime can reach 169.254.169.254, read AWS_* environment variables, call STS, or assume a role through IRSA or an ECS task role, a prompt-injection-driven tool abuse case can become cloud credential exposure.

Technical Analysis

Affected component: Amazon Bedrock AgentCore SDK and agent sandbox execution paths, as described by the referenced reporting. Exact vulnerable versions, root cause functions, and patched releases were not included in the provided summary. Do not wait for a CVE before reducing exposure. Validate against the AWS Security Bulletins page and the AgentCore release notes before declaring systems remediated.

Defender view of the attack chain:

  1. An attacker supplies hostile instructions through prompt injection, a poisoned tool result, a malicious document, a compromised MCP server, or an untrusted plugin.
  2. The agent runtime chooses a tool action that crosses a trust boundary, such as running Python, Node.js, shell, package installation, HTTP retrieval, or cloud SDK calls inside the sandbox.
  3. A flaw in SDK sandbox isolation or tool mediation permits command execution or broader local access than intended.
  4. The process attempts credential discovery: reading AWS_CONTAINER_CREDENTIALS_RELATIVE_URI, AWS_CONTAINER_CREDENTIALS_FULL_URI, AWS_WEB_IDENTITY_TOKEN_FILE, AWS_ROLE_ARN, ~/.aws/credentials, /proc environ data, or querying IMDS at 169.254.169.254.
  5. Temporary credentials are used with sts:GetCallerIdentity, sts:AssumeRole, iam:PassRole, secretsmanager:GetSecretValue, s3:GetObject, or other data-plane calls permitted by the attached role.

Exploitation requirements are likely to include control over agent input or tool output, an enabled execution-capable tool, network or metadata reachability from the sandbox, and an AWS identity attached to the compute or task. The highest-risk designs are agent runtimes that can execute code, install packages, make arbitrary network requests, and also inherit broad IAM permissions.

Exploitation status: based only on the provided item, there is no public CVE, no CVSS score, and no confirmation of inclusion in CISA KEV. Treat public reporting and researcher proof-of-concept claims as enough to trigger defensive validation. Do not fabricate a CVE in tickets or detections; track this under vendor product and technique identifiers until AWS publishes formal guidance.

Detection & Response

The detections below focus on high-signal behaviors rather than generic Python process noise. Tune the allowed agent runtime paths to your container image names, EKS node groups, ECS clusters, and CI runners before broad deployment.

YAML
---
title: AWS Agent Runtime Process Accessing Instance Metadata Credentials
id: 9d2d4d8f-5b1e-4b56-9a9b-5f0f8b63d101
status: experimental
description: Detects common agent runtimes or sandbox tools spawning commands that reference AWS instance metadata or credential endpoints.
references:
  - https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/
  - https://attack.mitre.org/techniques/T1552/005/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.credential_access
  - attack.t1552.005
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/python'
      - '/python3'
      - '/node'
      - '/java'
      - '/bash'
      - '/sh'
  selection_metadata:
    CommandLine|contains:
      - '169.254.169.254'
      - '/latest/meta-data/iam/security-credentials'
      - 'AWS_CONTAINER_CREDENTIALS_RELATIVE_URI'
      - 'AWS_CONTAINER_CREDENTIALS_FULL_URI'
      - 'AWS_WEB_IDENTITY_TOKEN_FILE'
  condition: all of selection_*
falsepositives:
  - AWS bootstrap scripts during controlled instance initialization
  - Legitimate IRSA or ECS agent health checks in known startup windows
level: high
---
title: Shell or Download Tool Spawned by AI Sandbox Runtime
id: 7be5f1d3-0c2a-4a4b-8c3a-0d4e61aa7202
status: experimental
description: Detects AI or automation runtimes spawning shells, interpreters, download tools, or AWS CLI in a way consistent with sandbox command execution and credential access staging.
references:
  - https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.execution
  - attack.t1059
  - attack.t1105
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentCommandLine|contains:
      - 'bedrock'
      - 'agentcore'
      - 'mcp'
      - 'langchain'
      - 'llama_index'
      - 'openai'
      - 'anthropic'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/curl'
      - '/wget'
      - '/aws'
      - '/python'
      - '/python3'
      - '/node'
      - '/nc'
      - '/socat'
  filter_benign_child:
    CommandLine|contains:
      - ' --version'
      - ' --help'
  condition: all of selection_* and not filter_benign_child
falsepositives:
  - Approved agent tool wrappers that intentionally invoke pinned binaries
  - Build agents and developer workstations with tightly scoped identities
level: medium
---
title: Network Connection From Agent Runtime to AWS Metadata Address
id: 3c91a0f8-83c5-4f0e-9a4d-7266bbbd5403
status: experimental
description: Detects network connections to the AWS link-local metadata address from processes commonly used for AI agent execution or sandbox tooling.
references:
  - https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/
  - https://attack.mitre.org/techniques/T1552/005/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.credential_access
  - attack.t1552.005
logsource:
  category: network_connection
  product: linux
detection:
  selection_ip:
    DestinationIp: '169.254.169.254'
  selection_proc:
    Image|endswith:
      - '/python'
      - '/python3'
      - '/node'
      - '/java'
      - '/curl'
      - '/wget'
      - '/aws'
      - '/bash'
      - '/sh'
  condition: all of selection_*
falsepositives:
  - Controlled startup metadata retrieval before agent tool execution begins
  - Host agents explicitly approved to query IMDS outside sandbox namespaces
level: high
KQL — Microsoft Sentinel / Defender
// Hunt for agent runtimes touching AWS metadata or credential material in Defender/Sentinel endpoint data.
let MetadataIndicators = dynamic(["169.254.169.254", "/latest/meta-data/iam/security-credentials", "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI", "AWS_CONTAINER_CREDENTIALS_FULL_URI", "AWS_WEB_IDENTITY_TOKEN_FILE", ".aws/credentials"]);
let AgentParents = dynamic(["python", "python3", "node", "java", "bash", "sh", "bedrock", "agentcore", "mcp", "langchain", "llama_index"]);
union isfuzzy=true
(DeviceProcessEvents
| where TimeGenerated > ago(7d)
| extend ParentLower = tolower(InitiatingProcessFileName), ProcLower = tolower(FileName), Cmd = tolower(ProcessCommandLine)
| where ParentLower in~ (AgentParents) or InitiatingProcessCommandLine has_any ("bedrock", "agentcore", "mcp", "langchain")
| where Cmd has_any (MetadataIndicators) or (ProcLower in~ ("curl", "wget", "aws", "bash", "sh", "nc", "socat") and Cmd has_any ("sts", "iam", "secretsmanager", "s3", "169.254.169.254"))
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName, InitiatingProcessId, ProcessId),
(Syslog
| where TimeGenerated > ago(7d)
| where SyslogMessage has_any (MetadataIndicators) and SyslogMessage has_any ("python", "node", "curl", "wget", "aws", "bedrock", "agentcore", "mcp")
| project TimeGenerated, HostName, ProcessName, ProcessID, SyslogMessage)
| order by TimeGenerated desc
KQL — Microsoft Sentinel / Defender
// CloudTrail hunt for suspicious use of temporary credentials after sandbox/runtime activity.
// Requires the AWS CloudTrail connector/table in Sentinel.
let Lookback = 7d;
AWSCloudTrail
| where TimeGenerated > ago(Lookback)
| where EventName in~ ("GetCallerIdentity", "AssumeRole", "GetSessionToken", "GetFederationToken", "GetSecretValue", "GetObject", "PassRole")
| where UserIdentityType =~ "AssumedRole" or UserAgent has_any ("aws-sdk", "Boto3", "botocore", "aws-cli")
| where SourceIpAddress !in~ (dynamic([])) // Add approved NAT/VPN egress ranges after validation
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Events=count(), Actions=make_set(EventName), Resources=make_set(ResourceType) by UserIdentityArn, SourceIpAddress, UserAgent, AwsRegion
| where Events > 20 or Actions has_any ("GetSecretValue", "PassRole", "AssumeRole")
| order by LastSeen desc
VQL — Velociraptor
-- Hunt endpoint processes and connections for AWS credential discovery from agent runtimes.
LET procs = SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(169\.254\.169\.254|meta-data/iam/security-credentials|AWS_CONTAINER_CREDENTIALS|AWS_WEB_IDENTITY_TOKEN_FILE|\.aws/credentials|sts|secretsmanager|assume-role)'
   OR Exe =~ '(?i)/(python3?|node|java|curl|wget|aws|bash|sh)$'
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime FROM procs
VQL — Velociraptor
-- Correlate metadata connections with likely agent or sandbox processes on Linux endpoints.
LET conns = SELECT Pid, Name, LocalAddr, LocalPort, RemoteAddr, RemotePort, State, Timestamp
FROM netstat()
WHERE RemoteAddr =~ '169\.254\.169\.254'
SELECT c.Pid AS Pid, c.Name AS ProcessName, p.Exe AS Exe, p.CommandLine AS CommandLine,
       c.RemoteAddr AS RemoteAddr, c.RemotePort AS RemotePort, c.State AS State, c.Timestamp AS Timestamp
FROM conns AS c
LEFT JOIN pslist() AS p ON c.Pid = p.Pid
WHERE p.Exe =~ '(?i)/(python3?|node|java|curl|wget|aws|bash|sh)$' OR p.CommandLine =~ '(?i)(bedrock|agentcore|mcp|langchain|llama)'
Bash / Shell
#!/usr/bin/env bash
# Defensive validation for Linux hosts/containers running AWS agent or sandbox workloads.
# Run read-only checks first. Apply network changes only in a maintenance window or via image/IaC.
set -euo pipefail

echo "[1] Check for ambient AWS credentials in the current shell/container"
env | grep -E '^(AWS_ACCESS_KEY_ID|AWS_SECRET_ACCESS_KEY|AWS_SESSION_TOKEN|AWS_CONTAINER_CREDENTIALS|AWS_WEB_IDENTITY_TOKEN_FILE|AWS_ROLE_ARN)=' || true

echo "[2] Check whether IMDSv2 is required on this EC2 instance, when instance-id is available"
TOKEN="$(curl -sS -m 2 -X PUT 'http://169.254.169.254/latest/api/token' -H 'X-aws-ec2-metadata-token-ttl-seconds: 60' || true)"
if [ -n "$TOKEN" ]; then
  IID="$(curl -sS -m 2 -H "X-aws-ec2-metadata-token: $TOKEN" http://169.254.169.254/latest/meta-data/instance-id || true)"
  echo "instance-id=$IID"
else
  echo "IMDS not reachable from this namespace, already blocked, or token request denied"
fi

echo "[3] Show existing egress rules that mention the metadata address"
(iptables -S 2>/dev/null || true) | grep '169.254.169.254' || true
(nft list ruleset 2>/dev/null || true) | grep '169.254.169.254' || true

echo "[4] List suspicious agent/runtime processes touching metadata or credential terms"
ps -eo pid,ppid,user,comm,args | grep -Ei 'bedrock|agentcore|mcp|langchain|python|node|java|curl|wget|aws' | grep -Ei '169\.254\.169\.254|meta-data|AWS_CONTAINER_CREDENTIALS|WEB_IDENTITY|\.aws/credentials|assume-role|secretsmanager' || true

echo "[5] Optional containment: block metadata egress for a dedicated sandbox UID or cgroup. Replace 1500 with your sandbox UID."
echo "Example only: iptables -A OUTPUT -m owner --uid-owner 1500 -d 169.254.169.254/32 -j REJECT"
echo "Prefer IaC/image enforcement. For EC2: aws ec2 modify-instance-metadata-options --instance-id <i-id> --http-tokens required --http-endpoint enabled"

echo "[6] Rotation reminder: if exposure is suspected, rotate role sessions and revoke active credentials via IAM/STS and Secrets Manager runbooks."

Response actions if detection fires:

  • Isolate the host, pod, task, or developer workstation from production data paths. Preserve container filesystem and process memory before killing the sandbox.
  • Treat any exposed temporary credential as compromised. Revoke active sessions, rotate secrets accessible to the role, and review CloudTrail for use after first suspicious command execution.
  • Capture agent prompts, tool inputs and outputs, MCP server configurations, installed package versions, SDK version, container image digest, IAM role ARN, and network flow logs.
  • Check whether the process was able to retrieve role credentials, not merely reach IMDS. A blocked token request is different from a returned AccessKeyId and SessionToken.
  • Review downstream control-plane and data-plane calls for sts:AssumeRole, iam:PassRole, secretsmanager:GetSecretValue, s3:GetObject, kms:Decrypt, and events:PutEvents used for persistence or exfiltration.

Remediation

Until AWS publishes explicit fixed versions or a CVE, prioritize compensating controls that remove credential reachability from agent execution paths.

  • Upgrade the Amazon Bedrock AgentCore SDK and agent runtime only after confirming the fixed release in official AWS Security Bulletins and release notes. Pin dependencies by digest, rebuild images, and verify the package hash inside the running container rather than trusting build-time labels.
  • Enforce IMDSv2 with hop limit 1 on EC2, and block metadata access from sandbox namespaces, tasks, pods, and UIDs that do not require it. Require --http-tokens required, keep --http-endpoint enabled only where needed, and avoid broad container access to the node metadata path.
  • Remove ambient credentials from agent environments. Do not place long-lived AWS keys in environment variables, mounted files, or agent memory. Prefer narrowly scoped IAM roles with short sessions, explicit external IDs where applicable, resource-level permissions, and deny statements for iam:PassRole, iam:CreateRole, sts:AssumeRole on sensitive roles, secretsmanager access outside approved secret ARNs, and kms:Decrypt outside approved keys.
  • Segment tool trust. Disable arbitrary shell, package install, browser retrieval, code execution, and network egress tools unless a business workflow requires them. Require allowlisted domains, pinned MCP servers, signed tool definitions, and human approval for high-impact actions.
  • Add an egress proxy for agent traffic and deny direct RFC1918/link-local access except approved services. Alert on any agent runtime connecting to 169.254.169.254, instance identity document paths, ECS task metadata endpoints, or EKS IRSA token paths outside startup.
  • Add CloudTrail detection for anomalous first use of assumed-role sessions, impossible travel for service roles, sudden GetSecretValue volume, and data-plane reads from new source IPs. Correlate endpoint telemetry with CloudTrail by UserIdentityArn and SourceIpAddress.
  • If exposure is confirmed, rotate credentials and revoke sessions immediately, expire OIDC/IRSA tokens where feasible, rotate secrets reachable by the role, invalidate presigned URLs, and review downstream resources for unauthorized persistence such as new access keys, role trust policy changes, Lambda event mappings, or SSM documents.

Authoritative sources to monitor: AWS Security Bulletins at https://aws.amazon.com/security/security-bulletins/, Amazon Bedrock and AgentCore documentation/release notes, the referenced Infosecurity Magazine report, and CISA KEV at https://www.cisa.gov/known-exploited-vulnerabilities-catalog. Re-check status after AWS confirms affected versions; update change tickets with the formal identifier only when published by AWS or NVD.

Related Resources

Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.