CVE-2026-95985
Received Received - Intake

Remote Code Execution in Amazon Kiro IDE

Vulnerability report for CVE-2026-95985, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: AMZN

Description

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amazon kiro_ide to 1.0.242 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-349 The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Amazon Kiro IDE versions before 1.0.242 allows remote unauthenticated actors to inject crafted instructions into the agent's context. This happens when a user runs the agent in a crafted repository as an untrusted workspace, enabling message-based modifications to auto-loaded global configuration paths.

Detection Guidance

Check the installed version of Amazon Kiro IDE by running: ki ro --version. If the version is before 1.0.242, the system is vulnerable. Review the global Kiro configuration directory (~/.kiro) for unexpected entries.

Impact Analysis

If exploited, this vulnerability could allow attackers to modify the agent's behavior or configuration without authentication. Users running the agent in untrusted workspaces on vulnerable versions risk unauthorized changes to their global Kiro configuration (~/.kiro directory).

Mitigation Strategies

Upgrade Amazon Kiro IDE to version 1.0.242 or later. If you previously ran the agent in an untrusted workspace, review the global Kiro configuration directory (~/.kiro) for unauthorized entries and remove them.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95985. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart