Skip to content
CoreBreak Vulnerability Exposes AI Agent Frameworks to Unauthorized Tool Use

CoreBreak Vulnerability Exposes AI Agent Frameworks to Unauthorized Tool Use

First seen 7 Aug 2026, 08:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 8, 2026 at 08:07 UTC

Security researchers revealed multiple vulnerabilities in AI agent frameworks, allowing unauthorized tool use and potential remote code execution (RCE). The CoreBreak vulnerability affects Amazon Web Services (AWS), Google, and Vercel, with AWS's InvokeHarness API being a primary target. AWS assigned CVE-2026-18830 to a flaw enabling attackers to bypass model authorization and invoke tools directly. While AWS and Google have patched their respective vulnerabilities, the Strands Python SDK remains unpatched. The flaws were disclosed during Black Hat USA 2026, highlighting risks in agent orchestration and tool execution logic. The vulnerabilities could lead to significant security breaches if exploited. The overall impact spans multiple frameworks, including LangChain and Microsoft Agent Framework, with various attack vectors identified.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-07-16
Google patches vulnerabilities in ADK
Google released fixes for the ADK, addressing issues including a continuation-forgery vulnerability.
Mallory.Ai
2026-07-20
CVE-2026-64650 and CVE-2026-64651 published
Two vulnerabilities were disclosed affecting various AI frameworks, including LangChain.
Mallory.Ai
2026-07-29
CVE-2026-18236 published
Google published a CVE for a vulnerability in the ADK that allowed insecure deserialization.
Mallory.Ai
2026-08-04
CVE-2026-18830 published
AWS assigned CVE-2026-18830 for a vulnerability in the InvokeHarness API that allowed unauthorized tool invocation.
Techtimes
2026-08-06
CoreBreak vulnerability disclosed at Black Hat USA 2026
Researchers presented findings on the CoreBreak vulnerability affecting multiple AI frameworks, including AWS and Google.
Techtimes

More articles in this cluster (9)

Following this threat?

Track Amazon Web Services and CVE-2026-18236 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed