A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
AI Summary
Unit 42 researchers identified a security issue in AWS AgentCore Harness where default configurations allow attackers to exfiltrate plaintext credentials from AgentCore Identity via prompt injection. The built-in shell tool, enabled by default and running as root, can access the memory space of the harness process (PID 1), where credentials are temporarily stored in plaintext during runtime. By injecting malicious commands through a support ticket, an attacker can execute reconnaissance and exfiltrate a JSON Web Token (JWT) used for downstream MCP server authentication. This stolen credential, belonging to the operator's service account (mcp-service), enables unauthorized access to sensitive data such as personally identifiable information (PII). AWS acknowledged the finding but classified it under customer responsibility, emphasizing proper scoping of allowedTools and egress filtering.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | webhook[.]site | Details → |