Unit 42 Reveals Critical Sandbox Vulnerabilities in AWS Bedrock AgentCore
Palo Alto Networks' Unit 42 has uncovered critical security vulnerabilities in Amazon Bedrock AgentCore, specifically targeting its Code Interpreter sandbox. The research demonstrates that the sandbox's network isolation mode, originally marketed as providing complete isolation with no external access, can be bypassed using DNS tunneling. This technique allows attackers to establish a covert bi-directional channel for data exfiltration from the supposedly offline environment. Additionally, the investigation identified a severe security regression involving the AgentCore Runtime's use of a microVM Metadata Service (MMDS) without session token enforcement. This flaw could enable attackers to exploit server-side request forgery (SSRF) vulnerabilities to extract sensitive credentials, potentially compromising other agents and services within an AWS account. Unit 42 responsibly disclosed these findings to AWS, which subsequently implemented internal remediations and updated its developer documentation to reflect that sandbox mode offers limited, rather than complete, network isolation. The report emphasizes the importance of understanding internal mechanics of AI agent frameworks and leveraging platform-level controls for mitigation, as users cannot directly patch the managed environment.
Wire timeline
Unit 42 Reveals Critical Sandbox Vulnerabilities in AWS Bedrock AgentCore
Palo Alto Networks' Unit 42 has uncovered critical security vulnerabilities in Amazon Bedrock AgentCore, specifically targeting its Code Interpreter sandbox. The research demonstrates that the sandbox's network isolation mode, originally marketed as providing complete isolation with no external access, can be bypassed using DNS tunneling. This technique allows attackers to establish a covert bi-directional channel for data exfiltration from the supposedly offline environment. Additionally, the investigation identified a severe security regression involving the AgentCore Runtime's use of a microVM Metadata Service (MMDS) without session token enforcement. This flaw could enable attackers to exploit server-side request forgery (SSRF) vulnerabilities to extract sensitive credentials, potentially compromising other agents and services within an AWS account. Unit 42 responsibly disclosed these findings to AWS, which subsequently implemented internal remediations and updated its developer documentation to reflect that sandbox mode offers limited, rather than complete, network isolation. The report emphasizes the importance of understanding internal mechanics of AI agent frameworks and leveraging platform-level controls for mitigation, as users cannot directly patch the managed environment.
Unit 42