Impact
Amazon Bedrock AgentCore harness contains insufficient input validation in the InvokeHarness API. This weakness allows an authenticated user to craft content blocks in conversation messages that cause the system to execute preconfigured tools, effectively bypassing the intended model invocation flow and built‑in security controls. The result is that the attacker can run arbitrary tool commands as the agent, potentially gaining higher privileges or escalating their authority within the environment. This is a classic input validation flaw (CWE-1287).
Affected Systems
The vulnerability originally affected the Amazon Bedrock AgentCore harness service. AWS has already addressed this issue, so all current deployments are considered patched and no customer action is required.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity; however, the fix applied by AWS removes the current risk. Since the EPSS score is not available, the likelihood of exploitation in the wild is low. The vulnerability required authentication to the Amazon Bedrock service and access to the InvokeHarness API. It is not listed in the CISA KEV catalog. Under the current fix, no exploitation risk exists.
OpenCVE Enrichment