Single Prompt Could Hijack All AI Agents in AWS Region Due to Permission Flaw
Zenity Labs reports that loose default permissions in AWS Bedrock AgentCore allowed cross-agent takeover via IMDS credential theft; AWS has tightened roles but manual least-privilege configuration remains critical.
ImportanceMaterialEvidenceE3 inspectableWrite-upDeep
A single chat message sent to a public-facing AI agent could steal its cloud identity credentials and take control of every other agent in the same AWS region.
Previously, Amazon Bedrock AgentCore allowed agents to access networks via built-in tools. Security firm Zenity Labs discovered that the platform's Firecracker microVMs failed to effectively block access to the internal Instance Metadata Service (IMDS). Researchers only needed to trick an agent into making one HTTP request to obtain temporary STS credentials, container image URIs, and internal keys. Because the default execution role applied to the entire region rather than individual agents, attackers could download all agent source code, read private conversations, and even tamper with long-term memory.
AWS responded after receiving the report in December 2025: new deployments now default to the more secure IMDSv2 protocol, and around August this year, the default execution role was tightened to prevent agents from invoking each other or retrieving credentials from Secrets Manager. Although the main entry point has been patched on the platform side, Zenity still recommends that companies not rely on default settings but instead manually create custom IAM roles with minimal necessary permissions to handle potential logical bypasses.
The vulnerability chain, dubbed "AgentCorruption," was disclosed by Zenity Labs on October 8. While AWS has released specific CVE patches for SDKs and CLIs, the core issue exposed here—the lateral movement capability of cloud agents lacking strict sandbox isolation—has not yet been independently reproduced by third parties, and Zenity's own business interest in selling AI security products warrants consideration of their disclosure motives.