news.mlab.sh
Back to the feed
vulnerability

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

High
Image: The Hacker News
Summary

Security flaws have been discovered in agent infrastructure used by AWS, Google, and Vercel, allowing attackers to bypass model checks and directly invoke tools without a legitimate model turn. These vulnerabilities stem from a lack of proper input validation and authorization, leading to potential tool misuse and access to sensitive operations. The fixes involve patching affected packages, rejecting caller-authored tool calls, and implementing strict authorization at execution time. The issues range from a remote request bypass in AWS to a confirmation forgery in Google's ADK and a process-path fallback in Vercel's AI SDK.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.