Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-64650
CVE
CVE-2026-64650
View on NVD ↗
AI SDK Codex Harness Tool Relay Authorization Bypass
Exploitation IoCs
3
Package
@ai-sdk/
[email protected]
Package
@ai-sdk/
[email protected]
Package
[email protected]
MITRE ATT&CK TTPs
3
T1059.001
PowerShell
Execution
T1078.004
Cloud Accounts
Defense Evasion
T1134.001
Token Impersonation/Theft
Defense Evasion
Source Articles
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Security researchers discovered critical flaws in agent infrastructures from AWS, Google, and Vercel that allow attackers to bypass model authorization and directly trigger tool execution. The vulnerabilities, collectively named CoreBreak, stem from insufficient validation of tool-call inputs, enabling untrusted or forged instructions to reach execution without model oversight. AWS addressed CVE-2026-18830 in its managed Bedrock AgentCore service by adding server-side validation, while Google patched two separate issues in its Agent Development Kit (ADK) for Python, including CVE-2026-18236 for continuation forgery and a resumable-mode bypass. Vercel fixed two related authorization bypasses in its AI SDK harness packages, tracked as CVE-2026-64650 and CVE-2026-64651, which allowed sandboxed malicious code to invoke host tools without model authorization.
hacker-news
Aug 6, 2026