CVE-2026-4269

Source
https://cve.org/CVERecord?id=CVE-2026-4269
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4269.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-4269
Aliases
Published
2026-03-16T18:16:11.007Z
Modified
2026-04-10T05:43:25.781050Z
Severity
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build or have built the Toolkit after September 24, 2025. Any users on a version >=v0.1.13, and any users on previous versions who built the toolkit before September 24, 2025 are not affected.

To remediate this issue, customers should upgrade to version v0.1.13.

References

Affected packages

Git / github.com/aws/bedrock-agentcore-starter-toolkit

Affected ranges

Type
GIT
Repo
https://github.com/aws/bedrock-agentcore-starter-toolkit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "v0.1.13"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "v0.1.13"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.10
v0.1.11
v0.1.12
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4269.json"