AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

Jeff Liu··2 min read·AI
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
ListenAI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
0:00
--:--

Key Takeaways

  1. 1Amazon Bedrock's Code Interpreter sandbox permits data exfiltration via DNS queries.
  2. 2LangSmith suffered a high-severity URL injection leading to account takeover.
  3. 3SGLang contains unpatched remote code execution flaws via unsafe pickle deserialization.
  4. 4AWS recommends VPC mode and DNS firewalls for Bedrock, deeming DNS egress "intended."
  5. 5These vulnerabilities highlight critical gaps in network isolation and input validation for AI agents.
Recent security research has revealed critical vulnerabilities across leading artificial intelligence platforms, including Amazon Bedrock, LangSmith, and SGLang. These flaws expose sensitive data exfiltration pathways and enable remote code execution, challenging the core security assumptions of AI development environments. Organizations relying on these services now face an urgent mandate to reassess their configurations and implement stronger protective measures against sophisticated cyber threats.

Bedrock's DNS Flaw Undermines Network Isolation

Security researchers at BeyondTrust have detailed a novel method for exfiltrating sensitive data from AI code execution environments using domain name system (DNS) queries. The report highlights a significant flaw in Amazon Bedrock AgentCore Code Interpreter's sandbox mode, which allows outbound DNS queries despite being configured for "no network access." This oversight creates a pathway for attackers to bypass network isolation controls.

Attackers can exploit this behavior to establish bidirectional command-and-control channels and exfiltrate sensitive information. This becomes particularly dangerous if the AI's IAM role possesses overprivileged permissions to access AWS resources like S3 buckets. In such scenarios, an interactive reverse shell can be obtained, and commands executed stealthily via DNS queries. The flaw, which lacks a CVE identifier, carries a CVSS score of 7.5 out of 10.0.

While Amazon acknowledged the report, it determined the behavior to be "intended functionality rather than a defect." AWS now recommends customers use VPC mode instead of sandbox mode for complete network isolation. They also advise implementing a DNS firewall to filter outbound DNS traffic. Jason Soroko, a senior fellow at Sectigo, emphasized that "Operating within a VPC provides the necessary infrastructure for robust network isolation, allowing teams to implement strict security groups, network ACLs, and Route53 Resolver DNS Firewalls."

LangSmith and SGLang Face Critical Exploits

Beyond the Bedrock revelations, two other prominent AI tools, LangSmith and SGLang, are grappling with their own severe vulnerabilities. Miggo Security disclosed a high-severity security flaw in LangSmith (CVE-2026-25750), affecting both self-hosted and cloud deployments. This vulnerability, rated 8.5 on the CVSS scale, stems from a lack of validation on the `baseUrl` parameter, allowing for URL parameter injection.

A third flaw (CVE-2026-3989), rated 7.8, involves insecure deserialization in a crash dump replay utility. The CERT Coordination Center (CERT/CC) advises SGLang users to restrict access to service interfaces and implement network segmentation and access controls. This prevents unauthorized interaction with ZeroMQ endpoints and protects against potential compromises.

Related Articles

More insights on trending topics and technology

The Signal

What shipped in AI this week, with the sources.

One email a week.