Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
ID: de3b0231-0c34-5a4e-914f-f00652d47994
STIX ID: report--de3b0231-0c34-5a4e-914f-f00652d47994
Feed Name: Palo Alto Networks Unit 42
Threat Score
Palo Alto Networks Unit 42 research demonstrates that Amazon Bedrock AgentCore’s Code Interpreter sandbox mode could be bypassed using DNS tunneling to exfiltrate data and that the AgentCore Runtime’s microVM Metadata Service (MMDS) accepted unauthenticated metadata requests (MMDSv1-like behavior), enabling credential retrieval; the report includes PoC steps, impact analysis, disclosure timeline, and mitigation guidance from AWS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
