PT-2026-49284 · Kiro Ide · Kiro Ide
CVE-2026-11931
·
Published
2026-06-15
·
Updated
2026-06-15
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kiro IDE versions prior to 0.11.133
Description
Incorrect default permissions on macOS and Linux allow the authentication token cache file to be world-readable (0644) instead of restricted to the owner (0600). This configuration could expose the cache file to other local users or processes.
Recommendations
Upgrade to version 0.11.133 or later. After upgrading and restarting the application, the cache file permissions are automatically updated during the next token refresh.
In multi-user environments, reauthenticate to invalidate existing tokens.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiro Ide