Insecure deserialization in the job results processing component in Amazon Braket SDK beforeĀ 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results.
We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9291.json",
"cwe_ids": [
"CWE-502"
],
"cna_assigner": "AMZN"
}