CVE-2026-95985
8.8Amazon · Kiro IDE
Amazon Kiro IDE versions before 1.0.242 allow unauthenticated remote actors to inject malicious instructions into the agent context, leading to unauthorized modifications of global configuration paths.
Executive summary
A critical vulnerability in Amazon Kiro IDE allows unauthenticated attackers to achieve remote code execution or unauthorized configuration modification by injecting malicious instructions into the agent.
Vulnerability
The vulnerability involves the inclusion of functionality from an untrusted control sphere, where the file write tool fails to sanitize inputs. An unauthenticated attacker can exploit this by enticing a user to open a crafted repository, allowing the agent to modify sensitive global configuration files.
Business impact
Successful exploitation of this flaw grants an attacker the ability to modify global IDE configurations, which can be leveraged to execute arbitrary code or compromise the integrity of the development environment. With a CVSS score of 8.8, this vulnerability represents a high-severity risk that could lead to full system compromise of the developer workstation and potential lateral movement into the corporate network.
Remediation
Immediate Action: Update Amazon Kiro IDE to version 1.0.242 or later immediately to patch the vulnerable file write tool.
Proactive Monitoring: Review the global Kiro configuration directory located at ~/.kiro for any unauthorized entries or suspicious modifications if the software was used with untrusted repositories.
Compensating Controls: Avoid opening untrusted or unknown repositories within the Kiro IDE until the software has been updated to the secure version.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for unauthorized system modification and the high CVSS severity, administrators and developers must prioritize the update to version 1.0.242. Users should perform a manual audit of their global Kiro configuration files to ensure no malicious persistence mechanisms were introduced prior to the application of the patch.
More Amazon CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section