
CVE-2026-18830, CVE-2026-18236, CVE-2026-64650, CVE-2026-64651: AWS, Google, Vercel Agent SDKs — Tool Execution Bypass Flaws (August 2026)
CVE-2026-18830, CVE-2026-18236, CVE-2026-64650, CVE-2026-64651 — AWS, Google, Vercel Agent SDKs
Four high-severity vulnerabilities (CVE-2026-18830, CVE-2026-18236, CVE-2026-64650, CVE-2026-64651) in AWS, Google, and Vercel agent infrastructure allow attackers to execute tools directly, bypassing model invocation and all associated guardrails. No evidence of active exploitation has been reported as of August 2026, but the attack surface is broad and risk is significant. CVSS scores are pending, but all vendors classify these as high impact. Patches are available as of mid-2026 and should be applied immediately.
Attack Vector
Attackers exploit flaws in agent SDKs and APIs to forge or inject tool execution instructions, bypassing model-level authorization, system prompts, and content filters. In AWS, the managed InvokeHarness API could be abused to trigger tool execution without a valid model call. Google’s ADK for Python exposed two separate bypasses, both allowing unauthorized tool execution through crafted API calls. Vercel’s SDKs permitted sandboxed local code to invoke sensitive host tools, including secret lookups, deployment operations, and access to cloud APIs, without proper validation. No authentication or privilege escalation was required beyond access to the agent interface.
Who Is at Risk
Affected products include AWS managed agent infrastructure (InvokeHarness API), Google ADK for Python (all versions prior to the mid-2026 patch), and all Vercel agent SDKs prior to their respective security updates. Any organization using these SDKs in production or development environments is exposed, with risk highest where agents are integrated with sensitive backend tools or cloud operations. Amazon Web Services, Google, and Vercel are confirmed affected.
Patch & Mitigate
- Patch: Apply vendor patches released mid-2026 for AWS InvokeHarness, Google ADK for Python, and Vercel agent SDKs. Review vendor advisories for exact versions.
- Workaround: Restrict agent SDK access to trusted sources only. Disable tool execution features if not required until patched.
- Detect: Audit agent logs for tool execution events lacking corresponding model invocation. Monitor for anomalous API calls or unauthorized tool access from agent endpoints.
MITRE ATT&CK
- T1210 — Exploitation of Remote Services: Attackers leverage exposed agent APIs to trigger unauthorized tool execution.
- T1566 — Phishing: Attackers may use compromised agent interfaces as a foothold for further access or lateral movement.
- T1078 — Valid Accounts: Abuse of legitimate agent credentials or API tokens to bypass model guardrails.
Source: https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

