PT-2026-98205 · Amazon · Kiro Ide

CVE-2026-95985

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amazon Kiro IDE versions prior to 1.0.242
Description The file write tool allows remote unauthenticated actors to inject crafted instructions into the agent's context. This occurs when a user runs the agent within a crafted repository as an untrusted workspace, where sending any message can lead to agent modifications of auto-loaded global configuration paths.
Recommendations Update to version 1.0.242 or later. Review the global Kiro configuration directory ~/.kiro for unauthorized entries if the agent was previously run in an untrusted workspace.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95985

Affected Products

Kiro Ide