logo

Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox

ID: de3b0231-0c34-5a4e-914f-f00652d47994

STIX ID: report--de3b0231-0c34-5a4e-914f-f00652d47994

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-28

Author: Ori Hadad

...
...

Palo Alto Networks Unit 42 research demonstrates that Amazon Bedrock AgentCore’s Code Interpreter sandbox mode could be bypassed using DNS tunneling to exfiltrate data and that the AgentCore Runtime’s microVM Metadata Service (MMDS) accepted unauthenticated metadata requests (MMDSv1-like behavior), enabling credential retrieval; the report includes PoC steps, impact analysis, disclosure timeline, and mitigation guidance from AWS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.