AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
AI Summary
Security researchers discovered critical flaws in agent infrastructures from AWS, Google, and Vercel that allow attackers to bypass model authorization and directly trigger tool execution. The vulnerabilities, collectively named CoreBreak, stem from insufficient validation of tool-call inputs, enabling untrusted or forged instructions to reach execution without model oversight. AWS addressed CVE-2026-18830 in its managed Bedrock AgentCore service by adding server-side validation, while Google patched two separate issues in its Agent Development Kit (ADK) for Python, including CVE-2026-18236 for continuation forgery and a resumable-mode bypass. Vercel fixed two related authorization bypasses in its AI SDK harness packages, tracked as CVE-2026-64650 and CVE-2026-64651, which allowed sandboxed malicious code to invoke host tools without model authorization.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 3 extracted
| Type | Value | Detail |
|---|---|---|
| Package | @ai-sdk/[email protected] | Details → |
| Package | @ai-sdk/[email protected] | Details → |
| Package | [email protected] | Details → |