Remote Code Injection in Amazon Kiro IDE Versions Prior to 1.0.242
CVE-2026-95985
8.6HIGH
What is CVE-2026-95985?
The file write tool within Amazon Kiro IDE versions prior to 1.0.242 has a vulnerability that enables remote unauthenticated users to inject malicious commands into the agent's execution context. This issue arises when the agent is executed in a potentially unsafe repository designated as an untrusted workspace. This manipulation can lead to unintended modifications to the agent's global configuration paths, posing significant risks to system security. Users are advised to upgrade to version 1.0.242 and inspect their global Kiro configuration directory for any unauthorized entries.
Affected Version(s)
Kiro IDE MacOS 0 < 1.0.242
