← BACK TO FEED
TAG

vercel ai sdk1 articles

Tool Without a Model: How AWS, Google, and Vercel Let Attackers Hijack Agent Actions

Security researchers discovered vulnerabilities in AI agent infrastructure from AWS, Google, and Vercel that allowed attackers to trigger tool executions without a legitimate model turn, bypassing system prompts, content filters, and model-level guardrails entirely. The flaws, collectively dubbed "CoreBreak," affected Amazon Bedrock AgentCore's InvokeHarness API, Google's Agent Development Kit for Python, and Vercel's AI SDK harness packages for Codex and OpenCode agents, with attack conditions ranging from authenticated remote requests to forged session events and sandbox escapes. All three vendors have issued patches, with the fixes sharing a common principle: binding each tool invocation to a verified model-authorized event rather than trusting the shape of incoming data alone.

9 Aug 2026