Kiro Ide Amazon Kiro Ide

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Amazon Kiro Ide.

Recent Amazon Kiro Ide Security Advisories

Advisory Title Published
2026-09-24 CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces September 24, 2026
2026-09-11 CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026
2026-08-04 CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows August 4, 2026
2026-06-15 CVE-2026-11931 - Insecure Permissions on Authentication Token Cache File in Kiro IDE June 15, 2026
2026-06-02 CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths June 2, 2026
2026-04-14 CVE-2026-5429 - Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme April 14, 2026
2026-03-17 Arbitrary code execution via crafted project files in Kiro IDE March 17, 2026

By the Year

In 2026 there have been 2 vulnerabilities in Amazon Kiro Ide with an average score of 8.3 out of ten.

Year Vulnerabilities Average Score
2026 2 8.30

It may take a day or so for new Kiro Ide vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Amazon Kiro Ide Security Vulnerabilities

Amazon Kiro IDE <1.0.242 Remote Code Injection via Agent Context
CVE-2026-95985 8.8 - High - September 24, 2026

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.

Inclusion of Functionality from Untrusted Control Sphere

Kiro IDE Uncontrolled Search Path (1.0.227) Windows
CVE-2026-18656 7.8 - High - August 04, 2026

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.

DLL preloading

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Amazon Kiro Ide or by Amazon? Click the Watch button to subscribe.

Amazon
Vendor

subscribe