CVE-2026-89332 in Aws and Amazon Products
Published on September 11, 2026
Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
Vulnerability Analysis
CVE-2026-89332 is exploitable with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Types
Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor. Sensitive information could include data that is sensitive in and of itself (such as credentials or private messages), or otherwise useful in the further exploitation of the system (such as internal file system structure).
Products Associated with CVE-2026-89332
stack.watch emails you whenever new vulnerabilities are published in Aws Kiro Ide or Amazon Aws. Just hit a watch button to start following.
Affected Versions
AWS Kiro IDE:- Before 0.8.135 is affected.