Insertion of Sensitive Information into Log File Affecting bedrock-agentcore package, versions [1.4.8,1.5.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insertion of Sensitive Information into Log File vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-BEDROCKAGENTCORE-18016322
  • published19 Jul 2026
  • disclosed16 Jul 2026
  • creditUnknown

Introduced: 16 Jul 2026

CVE-2026-15737  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

Upgrade bedrock-agentcore to version 1.5.1 or higher.

Overview

bedrock-agentcore is an An SDK for using Bedrock AgentCore

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File through the entrypoint invocation path and _emit_invocation_otel_attributes OpenTelemetry helper. An attacker can expose raw prompts and full agent responses by sending normal agent invocations that are recorded into agentcore.invocation.user_prompt and agentcore.invocation.agent_response span attributes. Those spans are exported to the customer’s aws/spans CloudWatch log group, where anyone with CloudWatch Logs read access can retrieve potentially sensitive user input and model output.

CVSS Base Scores

version 4.0
version 3.1