Unit 42 researchers discovered critical vulnerabilities in Amazon Bedrock AgentCore's Code Interpreter sandbox. Despite being advertised as providing 'complete isolation with no external network access,' the sandbox mode was found to permit recursive DNS queries to arbitrary public domains, enabling DNS tunneling for
Table of contents
AgentCore Architecture and IsolationPhase 1: Internal ReconnaissancePhase 2: The Clue in the MetadataPhase 3: The Great EscapePhase 4: Beyond the SandboxSort: