AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
ResearchBedrock AgentCoreAgent Development KitOur summary
Researchers disclosed authorization flaws in AWS Bedrock AgentCore, Google's Agent Development Kit, and Vercel's AI SDK that allowed unauthorized tool execution by bypassing model-level checks. In several scenarios, the underlying language models never processed the input, rendering standard safety guardrails ineffective. All three vendors have deployed fixes; users should update to ADK 2.5.0, @ai-sdk/harness-codex 1.0.29, and @ai-sdk/harness-opencode 1.0.28 to mitigate risks associated with CVE-2026-18830, CVE-2026-18236, CVE-2026-64650, and CVE-2026-64651.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.