Back to vendor advisories
AWS Security BulletinsCVE-2026-107322

CVE-2026-107322 - OS command injection in Amazon Agent Plugins for AWS databases-on-aws

Severity not listed 1 CVE Published Oct 8, 2026 at 7:29 PM UTC

Summary

Bulletin ID: 2026-130-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/08/2026 11:30 AM PDT

Description:

Amazon Agent Plugins for AWS is an open source collection of plugins that extends supported AI coding agents with AWS-focused workflows and tool integrations. The databases-on-aws plugin provides database design, development, migration, and operational guidance, including Aurora DSQL helper scripts.

We identified CVE-2026-107322, where an incomplete list of disallowed inputs in databases-on-aws versions before 1.7.1 could allow a remote unauthenticated actor to supply crafted content that an agent ingests. The affected code is not a listening network service; operating-system command execution on the host is possible only if the agent subsequently invokes the local helper with the crafted database command value.

Any resulting command runs with the permissions of the process running the helper. This issue does not affect the Aurora DSQL service or bypass database privileges.

Impacted versions: databases-on-aws versions 1.0.0 through 1.7.0

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 1

Update history

What changed in later vendor updates

SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.

    • The vendor changed the advisory summary.

Updates

  1. Added to SecurityAlert

    We collected the advisory from the official source.

  2. Published by AWS

    The publication date reported by the vendor.