CVE-2026-10591
Received Received - Intake
Arbitrary Command Execution in Amazon Kiro IDE

Publication date: 2026-06-02

Last updated on: 2026-06-02

Assigner: AMZN

Description
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-02
Last Modified
2026-06-02
Generated
2026-06-02
AI Q&A
2026-06-02
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
amazon kiro_ide From 0.11 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2026-10591 is a vulnerability in the Amazon Kiro IDE before version 0.11 where insufficient access control restrictions in the file write tool allow remote unauthenticated actors to execute arbitrary commands.

This happens because attackers can craft instructions that write to execution-sensitive paths such as .vscode/tasks.json, which triggers automatic execution when a folder is opened.

The vulnerability enables attackers to run commands remotely without authentication, potentially compromising the system.


How can this vulnerability impact me? :

This vulnerability can have severe impacts including unauthorized remote code execution, which can lead to full compromise of the affected system.

  • Attackers can execute arbitrary commands remotely without needing any authentication.
  • It can result in high confidentiality, integrity, and availability impacts as indicated by the CVSS scores.
  • Malicious commands could be executed automatically when a user opens a folder, potentially spreading malware or stealing data.

How can this vulnerability be detected on my network or system? Can you suggest some commands?

There are no specific detection methods or commands provided to identify this vulnerability on your network or system.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, users should upgrade the Kiro IDE to version 0.11 or later.

No workarounds are available for this issue.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart