Skip to content

Build1 publisher3 min readPublished

AWS's AgentCore SDK needed two releases to close one injection bug in install_packages()

AWS's Bedrock AgentCore Python SDK shipped fixes in v1.6.1 and v1.18.1 for one argument-injection flaw in install_packages(). Teams that let agents or users name packages for Code Interpreter sandboxes should check those names before the SDK sees them.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying AWS's AgentCore SDK needed two releases to close one injection bug in install_packages()
Generated illustration

What happened

  • From v1.1.3 through v1.6.0, the helper joined caller-supplied strings into a pip install command with almost no validation, a flaw tracked as CVE-2026-12530.
  • BeyondTrust's Phantom Labs published its full research on September 28, including one injection path that used a newline to smuggle in a second command.
  • The second round, tracked as CVE-2026-16796, put command substitution inside pip's extras syntax, a form the first fix's validation did not inspect.
  • The v1.18.1 release note reads only "fix: tighten package specifier validation in install_packages()", with no CVE number and no mention of injection.
  • NVD scores both CVEs 7.3 under CVSS 3.1 and 8.4 under CVSS 4.0, and lists both as still awaiting analysis.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure A team that moved to v1.6.1 to close CVE-2026-12530 stayed inside the CVE-2026-16796 range, so the version floor to enforce in CI is 1.18.1.
  • constraint Teams that triage dependency bumps by scanning release notes for CVE identifiers had no signal to prioritise v1.18.1 over any other patch release.
  • exposure An agent that loads API keys or session tokens into sandbox environment variables puts them within reach of a crafted package name, whatever the sandbox-capped score says.
  • decision Builders who let a model or a user choose package names have reason to enforce their own allowlist before calling install_packages(), because the SDK's validation has already missed one pip form.

`install_packages()` exists so an agent can add libraries at runtime inside AgentCore's isolated Code Interpreter sandbox [1]. A dev.to post that traced both rounds published a simplified version of the code [3]. The helper joins the caller's strings with spaces, formats them into `pip install {pkg_str}`, and hands the line to `run_in_sandbox()` as one command string [3]. Every character of a package name reaches the shell, delimiters included [3]. The weakness class is CWE-88, argument injection [5].

A validation fix has to anticipate every form pip accepts as a package name. That grammar includes the bracketed extras form, `package[extra1,extra2]` [7]. Round two came through that form, in the same function and the same sink as round one, according to the post [7].

The v1.18.1 change combines shlex-based quoting with a tighter allowlist on which extras syntax is permitted, according to the post's reading of the linked commit and BeyondTrust's write-up [9]. I think that is the right design. Quoting makes the shell see each name as one argument whatever it contains. The allowlist limits what pip is asked to resolve. "That is the correct shape: parse, don't concatenate," the author wrote [10]. In the snippet, the sandbox call takes a single string [3]. If the real API accepts nothing else, quoting is the fix on offer, since there is no argument vector to pass.

The post opens with a stronger line. "Both fixes were bypassable, each in a different way," the author wrote [2]. The detail that follows documents one fix being bypassed, the extras route around the first, and endorses the v1.18.1 design [7][10]. The post does not describe a bypass of v1.18.1, so the evidence supports two rounds of one bug with the second fix still standing [9].

The CVSS vectors behind the NVD scores cap impact at the sandbox boundary [12]. The first advisory adds that a crafted name could point pip at an attacker-controlled package index and expose sandbox files and environment variables [13]. BeyondTrust titled its research "Package Name to Role Credentials in Code Interpreter", a chain the post's author has not reproduced [14]. The firm also published a companion repository, agentcore-sandbox-breakout, demonstrating DNS and S3 exfiltration paths from the same sandboxes [15].

For CI, the author runs a preflight script that exits 1 when the installed SDK sits in a vulnerable range [16]. Its table marks CVE-2026-12530 as affecting 1.1.3 up to 1.6.1, and CVE-2026-16796 as affecting everything below 1.18.1 with no lower bound [16]. Its `version_tuple()` casts each of the first three dot-separated segments to an integer [17]. A pre-release string such as 1.18.1rc1 would raise ValueError and stop the job, so the gate fails closed [2].

What to watch

  • NVD's own analysis of CVE-2026-12530 and CVE-2026-16796 could move both scores off their Secondary values.
  • An independent reproduction of BeyondTrust's package-name-to-role-credentials chain would take the impact past the sandbox boundary the CVSS vectors assume.
  • A third advisory against install_packages() after v1.18.1 would test whether shlex quoting plus the extras allowlist holds.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories