Zenity Labs reported a chain of vulnerabilities in Amazon Bedrock AgentCore to AWS on December 25, 2025, allowing a single prompt sent to one public agent to take over every agent in the same AWS account and region. The flaws, dubbed "AgentCorruption," exposed credentials, source code, private conversations, and agent memory. AWS has since tightened metadata access and default execution role permissions, though Zenity Labs recommends custom minimal-access roles.
No score is assigned. Sources and their independence are shown in the citation chain below.