CyberRota Analysis
AI-GeneratedThe file write tool in Amazon Kiro IDE versions prior to 1.0.242 is vulnerable to remote unauthenticated code injection, allowing attackers to manipulate the agent's context when executed in untrusted workspaces. This can lead to unauthorized modifications of global configuration paths, posing a significant security risk. Users of Kiro IDE, especially those operating in potentially untrusted environments, should prioritize upgrading to version 1.0.242 or later and audit their global configuration directories for any unauthorized changes.
Original NVD Description
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.