Amazon Kiro IDE <1.0.242 Remote Code Injection via Agent Context
CVE-2026-95985 Published on September 24, 2026
Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.
We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
Vulnerability Analysis
CVE-2026-95985 can be exploited with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Types
Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Acceptance of Extraneous Untrusted Data With Trusted Data
The software, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
Products Associated with CVE-2026-95985
Want to know whenever a new CVE is published for Amazon Kiro Ide? stack.watch will email you.
Affected Versions
Amazon Kiro IDE:- Before 1.0.242 is affected.