vulnti.work

AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user c…

Medium CVSS 5.7
CVECVE-2026-15737
First seen2026-07-17 19:16 UTC
Disclosed2026-07-16 18:16 UTC
Last updated2026-07-17 19:16 UTC
Channel statusauto

Summary

AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a local authenticated user with access to CloudWatch Logs to access raw user prompts and agent responses containing sensitive data via span attributes. The SDK wrote raw user prompts …

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Lint boundary warnings (2)

The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).

  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://aws.amazon.com/security/security-bulletins/2026-058-aws/
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://pypi.org/project/bedrock-agentcore/1.5.1/

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD