PT-2026-49284 · Kiro Ide · Kiro Ide

CVE-2026-11931

·

Published

2026-06-15

·

Updated

2026-06-15

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kiro IDE versions prior to 0.11.133
Description Incorrect default permissions on macOS and Linux allow the authentication token cache file to be world-readable (0644) instead of restricted to the owner (0600). This configuration could expose the cache file to other local users or processes.
Recommendations Upgrade to version 0.11.133 or later. After upgrading and restarting the application, the cache file permissions are automatically updated during the next token refresh. In multi-user environments, reauthenticate to invalidate existing tokens.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11931

Affected Products

Kiro Ide