CoreBreak Vulnerability Exposes AI Agent Frameworks to Unauthorized Tool Use

CoreBreak Vulnerability Exposes AI Agent Frameworks to Unauthorized Tool Use

First seen 7 Aug 2026, 08:28 UTC Mallory.AiTechtimesmalware.news 84% similarity 70.5

Article Content

Browse articles
ThreatCluster

Security researchers revealed multiple vulnerabilities in AI agent frameworks, allowing unauthorized tool use and potential remote code execution (RCE). The CoreBreak vulnerability affects Amazon Web Services (AWS), Google, and Vercel, with AWS's InvokeHarness API being a primary target. AWS assigned CVE-2026-18830 to a flaw enabling attackers to bypass model authorization and invoke tools directly. While AWS and Google have patched their respective vulnerabilities, the Strands Python SDK remains unpatched. The flaws were disclosed during Black Hat USA 2026, highlighting risks in agent orchestration and tool execution logic. The vulnerabilities could lead to significant security breaches if exploited. The overall impact spans multiple frameworks, including LangChain and Microsoft Agent Framework, with various attack vectors identified.

Key Points: • CoreBreak vulnerability allows unauthorized tool invocation in AI agent frameworks. • AWS's InvokeHarness API was assigned CVE-2026-18830 and patched on July 31, 2026. • Strands Python SDK remains unpatched, leaving a potential attack vector open.

ThreatCluster AI How this analysis works

Timeline

2026-07-16
Google patches vulnerabilities in ADK
Google released fixes for the ADK, addressing issues including a continuation-forgery vulnerability.
Mallory.Ai
2026-07-20
CVE-2026-64650 and CVE-2026-64651 published
Two vulnerabilities were disclosed affecting various AI frameworks, including LangChain.
Mallory.Ai
2026-07-29
CVE-2026-18236 published
Google published a CVE for a vulnerability in the ADK that allowed insecure deserialization.
Mallory.Ai
2026-08-04
CVE-2026-18830 published
AWS assigned CVE-2026-18830 for a vulnerability in the InvokeHarness API that allowed unauthorized tool invocation.
Techtimes
2026-08-06
CoreBreak vulnerability disclosed at Black Hat USA 2026
Researchers presented findings on the CoreBreak vulnerability affecting multiple AI frameworks, including AWS and Google.
Techtimes

Community

Browse all →