Description
A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build or have built the Toolkit after September 24, 2025. Any users on a version >=v0.1.13, and any users on previous versions who built the toolkit before September 24, 2025 are not affected.

To remediate this issue, customers should upgrade to version v0.1.13.
Published: 2026-03-16
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The Bedrock AgentCore Starter Toolkit fails to verify that objects stored in Amazon S3 belong to the correct owner before starting the build process. Because of this missing check, a remote actor can supply a malicious object, which the toolkit then executes during the build, leading to code execution inside the AgentCore Runtime. The weakness maps to CWE‑283 (Improper Access Control) and CWE‑340 (Cryptographic Logic Errors). S3 ownership verification is a critical security control, and its absence permits a remote adversary to execute arbitrary code, potentially compromising confidentiality, integrity, and availability of any application that relies on the toolkit.

Affected Systems

Only deployments of Bedrock AgentCore Starter Toolkit earlier than version v0.1.13 that were built or rebuilt after September 24, 2025 are vulnerable. Users on v0.1.13 or later, or users who built the toolkit before the stated date, are not affected. The vulnerability is relevant to any AWS customer who uses the starter toolkit in a custom application with its own S3 bucket integrations.

Risk and Exploitability

The CVSS score of 5.8 denotes moderate severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a remote actor injecting a malicious S3 object that the toolkit accepts during a build, a scenario that requires access to the S3 bucket used by the build process. Because the vulnerability requires configuration of the build environment, exploitation is not trivial, but the potential for arbitrary code execution makes it a significant concern for affected users.

Generated by OpenCVE AI on March 17, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Bedrock AgentCore Starter Toolkit to version v0.1.13.

Generated by OpenCVE AI on March 17, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xfhr-q72q-jcrj Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
History

Tue, 17 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Aws
Aws bedrock Agentcore Starter Toolkit
Vendors & Products Aws
Aws bedrock Agentcore Starter Toolkit

Mon, 16 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Description A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build or have built the Toolkit after September 24, 2025. Any users on a version >=v0.1.13, and any users on previous versions who built the toolkit before September 24, 2025 are not affected. To remediate this issue, customers should upgrade to version v0.1.13.
Title Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
Weaknesses CWE-283
CWE-340
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Aws Bedrock Agentcore Starter Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-03-16T18:12:08.533Z

Reserved: 2026-03-16T14:28:57.619Z

Link: CVE-2026-4269

cve-icon Vulnrichment

Updated: 2026-03-16T18:11:58.092Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-16T18:16:11.007

Modified: 2026-03-17T14:20:01.670

Link: CVE-2026-4269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-24T10:50:02Z

Weaknesses