Zenity Labs says a prompt sent to one public Amazon Bedrock AgentCore agent allowed its researchers to obtain temporary AWS credentials and reach other agents in the same account and region. The company calls the vulnerability chain AgentCorruption.
In a test environment, an AgentCore agent followed instructions to query AWS’s internal instance metadata service and send the response outside the platform. The retrieved credentials worked from a separate machine. Broad default permissions then allowed researchers to list and invoke agents, download code packages, read private conversations and access stored credentials.
Long-term agent memory created another route for persistence. Zenity says it altered memory so an agent would forward later conversations to an external destination. The research used accounts controlled by the researchers and does not show that unrelated customer environments were breached.
Zenity disclosed the findings to AWS in December 2025. AWS subsequently made the more restrictive IMDSv2 metadata service the default for new AgentCore deployments and narrowed the default execution role, removing access to other agents, conversations and Secrets Manager. Existing deployments still warrant review. Custom least-privilege roles and separation between public and internal agents remain necessary even after safer defaults.