logo

AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

ID: 4282c63a-f599-5a8c-af9f-e106f1626eaf

STIX ID: report--4282c63a-f599-5a8c-af9f-e106f1626eaf

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed several high-severity flaws and abuse techniques targeting AI execution and observability platforms: a method to establish bidirectional C2 and exfiltrate data via DNS from Amazon Bedrock AgentCore Code Interpreter sandbox (CVSS 7.5) when overprivileged IAM roles are present; a LangSmith URL parameter injection (CVE-2026-25750, CVSS 8.5) enabling bearer token theft and account takeover; and multiple unpatched SGLang pickle deserialization vulnerabilities (CVE-2026-3059/3060/3989, CVSS up to 9.8) that can lead to unauthenticated remote code execution. Vendors and researchers recommend migrating to VPC mode, using DNS firewalls, patching affected software, restricting network exposure, and enforcing least privilege on IAM roles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.