Tooling Flaws Allow Build-Time Code Execution and File Exposure

Bedrock AgentCore Starter Toolkit builds before v0.1.13 omitted S3 ownership verification. That omission can let a remote actor inject code during the build and cause code execution in the AgentCore Runtime for builds performed after Sept 24, 2025. Separately, AWS API MCP Server versions >=0.2.14 and <1.3.9 have a no-access/workdir path bypass that can expose arbitrary local files to MCP clients.

Part of the PlainSec briefing for 2026-03-18

Sources