CVE-2026-89332
Received Received - Intake

Inclusion of Untrusted Functionality in Amazon Kiro IDE

Vulnerability report for CVE-2026-89332, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: AMZN

Description

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened. To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amazon kiro_ide to 0.8.135 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135. It allows remote unauthenticated actors to access sensitive information from a developer's workstation by exploiting crafted repository content. The issue occurs when malicious content modifies the workspace settings file, redirecting registry requests to a controlled endpoint and sending workspace data when the Powers panel is opened.

Impact Analysis

If exploited, this vulnerability could allow attackers to steal sensitive data from your workstation, including credentials or project files. It may also lead to unauthorized access to your development environment or projects. Users who opened projects in vulnerable versions should rotate any exposed credentials.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for protecting sensitive data. Unauthorized access to personal or health information may result in legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Upgrade to Kiro IDE version 0.8.135 or later. If you opened a project in an earlier version, rotate any credentials that were present in that project.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89332. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart