CyberRota
← Ana sayfaya dön

CVE-2026-9255

HIGH · CVSS 7.8 EPSS %0.15

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-22T17:16:49.767 · Çekilme zamanı: 2026-06-20T12:03:41.798081+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-9255
Severity
HIGH
CVSS
7.8
EPSS
%0.15

Orijinal NVD Açıklaması

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later.