THREAT OPS › Threat News › [GHSA] GHSA-m4x6-gwgp-4pm7 (high) — AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
[GHSA] GHSA-m4x6-gwgp-4pm7 (high) — AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
GHSA-m4x6-gwgp-4pm7 Severity: high CVE: CVE-2026-11393
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
### Summary The AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. An issue exists where, under certain circumstances, a crafted collaborationInstruction value stored in B
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-11393cve
Original source: https://github.com/advisories/GHSA-m4x6-gwgp-4pm7