Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
Vulnerability: A critical flaw in Amazon Bedrock AgentCore’s Code Interpreter sandbox network isolation mode allows attackers to bypass restrictions and exfiltrate data via DNS tunneling.
Deep Analysis and Expert Commentary
A critical flaw in Amazon Bedrock AgentCore’s Code Interpreter sandbox network isolation mode allows attackers to bypass restrictions and exfiltrate data via DNS tunneling. This vulnerability undermines the core security promise of AgentCore, which isolates AI agents’ code execution from external networks. Additionally, the AgentCore Runtime’s microVM Metadata Service (MMDS) lacks session token en
Original Article Brief Intro
Palo Alto Unit 42 · 2026-04-07 · Vulnerability: A critical flaw in Amazon Bedrock AgentCore’s Code Interpreter sandbox network isolation mode allows attackers to bypass restrictions and exfiltrate data via DNS tunneling.
Related Terms and Notes
Techniques / TTPs
- Server-Side Request Forgery (SSRF) — A vulnerability where an attacker forces a server to make unauthorized requests to internal or external systems.
Context Notes
- AI Security
- Amazon Bedrock AgentCore
- DNS Tunneling — A technique used to bypass network restrictions by encoding data in DNS queries and responses.
- Server-Side Request Forgery