PT-2026-98205 · Amazon · Kiro Ide
CVE-2026-95985
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon Kiro IDE versions prior to 1.0.242
Description
The file write tool allows remote unauthenticated actors to inject crafted instructions into the agent's context. This occurs when a user runs the agent within a crafted repository as an untrusted workspace, where sending any message can lead to agent modifications of auto-loaded global configuration paths.
Recommendations
Update to version 1.0.242 or later.
Review the global Kiro configuration directory
~/.kiro for unauthorized entries if the agent was previously run in an untrusted workspace.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kiro Ide