Vulnerability in Kiro Powers Feature of Amazon Kiro IDE Affects Developer Workstations
CVE-2026-89332

6.7MEDIUM

Key Information:

Vendor

Aws

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89332?

A vulnerability in the Kiro Powers feature of Amazon Kiro IDE allows untrusted control sphere functionalities. Prior to version 0.8.135, this flaw can be exploited by remote unauthenticated actors, potentially exposing sensitive information stored on developer workstations. Attackers can craft repository content that alters the workspace settings file, redirecting registry requests towards malicious endpoints. This action can lead to unauthorized exposure of workspace data when users open the Powers panel. Users are strongly advised to upgrade to Kiro IDE version 0.8.135 or later and to ensure they rotate any credentials used in projects opened with earlier versions.

Affected Version(s)

Kiro IDE 0 < 0.8.135

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.