Skip to content
Zenteck
Latest
Analysis

AWS Bedrock AgentCore flaw let single prompt hijack agents

2 min read0 comments
failure-in-aws-bedrock-agentcore-allowed-kidnapping-agents
Photo: ZenteckFailure in aws bedrock agentcore allowed kidnapping agents

According to security firm Zenity Labs, a single chat message to a public-facing assistant on Amazon's Bedrock AgentCore platform could compromise an entire AWS account and region. The researchers uncovered a vulnerability chain that bypassed sandbox boundaries, allowing an attacker to extract internal AWS credentials and manipulate every other agent in the same environment.

How did a single prompt breach cloud credentials?

Agents running on the platform lacked proper isolation from AWS's internal Instance Metadata Service. When the researchers asked a test agent in plain language to query the metadata service at 169.254.169.254 and transmit the results externally, the agent followed the instructions without restriction. The service returned full temporary AWS credentials, including keys and session tokens, which remained valid outside the platform.

Why were all agents in the region exposed?

The takeover escalated because AgentCore's default permissions applied broadly across every agent in the same region, rather than isolating individual workloads. With the stolen credentials and overly broad execution roles, researchers could list every agent, download their code packages in seconds, and invoke them remotely. This exposed stored passwords, private user conversations, and allowed memory poisoning to alter the behavior of other internal agents.

What changes for development teams using cloud agents?

Although AWS has updated default execution roles to restrict agents from invoking other agents or reading secrets manager data, security experts emphasize that default settings remain insufficient. Development teams must manually configure custom roles with strict, minimal access rights to ensure that public-facing customer service agents cannot interact with internal financial or operational systems.

Sources

  1. A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found — the-decoder.com

Frequently asked questions

What caused the Bedrock AgentCore security flaw?
The platform lacked proper isolation from the internal metadata service, allowing agents to retrieve temporary AWS credentials when prompted.
How many agents were affected in an attack?
Because default execution roles were overly broad, compromising one public agent allowed researchers to access every agent in the same AWS account and region.
Has Amazon patched the vulnerability?
Yes, AWS made IMDSv2 the default and tightened execution roles to prevent agents from invoking each other or reading secrets manager data.