THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m4x6-gwgp-4pm7 (high) — AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

[GHSA] GHSA-m4x6-gwgp-4pm7 (high) — AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

medgithub_advisoriesPublished 2026-07-29

GHSA-m4x6-gwgp-4pm7 Severity: high CVE: CVE-2026-11393

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

### Summary The AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. An issue exists where, under certain circumstances, a crafted collaborationInstruction value stored in B

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m4x6-gwgp-4pm7