CVE-2026-7191- Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS
Bulletin ID: 2026-020-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/27 13:15 PM PDT Description: QnABot on AWS is an open-source solution that provides a multi-channel, multi-language conversational interface powered by Amazon Lex, Amazon OpenSearch Service, and optionally Amazon Bedrock. We identified CVE-2026-7191, where the improper use of the static-eval npm package may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context. By injecting a crafted conditional chaining expression via the Content Designer interface, an actor with Admin access could bypass the intended expression sandbox through JavaScript prototype manipulation. Successful exploitation may grant direct access to backend resources, including Lambda environment variables, OpenSearch indices, S3 objects, and DynamoDB tables, that are not exposed through normal administrative interfaces. Impacted versions: <=7.2.4 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Improper use of the static-eval npm package may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context.
- Who is affected
- Authenticated administrators of QnABot on AWS.
- Urgency
- Remediation is urgent due to the risk of arbitrary code execution and access to backend resources.
- Action
- Review and secure the use of the static-eval npm package.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch QnABot
Get an email when a new QnABot advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-020-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-71910.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7191 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - Arbitrary Code
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownFURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additi…jvn · 2026-08-26
- highCVE-2026-79845: A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerabilit…nvd · 2026-08-25
- unknownCVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the…nvd · 2026-08-25
- unknownCVE-2026-62862: Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1,…nvd · 2026-08-25
- unknownCVE-2026-38468: A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterW…nvd · 2026-08-25
- mediumCVE-2026-79793: A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this v…nvd · 2026-08-25
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownOngoing updates on Copy.fail and variants2026-08-20