OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-95985

HIGH · CVSS 8.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The file write tool in Amazon Kiro IDE versions prior to 1.0.242 is vulnerable to remote unauthenticated code injection, allowing attackers to manipulate the agent's context when executed in untrusted workspaces. This can lead to unauthorized modifications of global configuration paths, posing a significant security risk. Users of Kiro IDE, especially those operating in potentially untrusted environments, should prioritize upgrading to version 1.0.242 or later and audit their global configuration directories for any unauthorized changes.

CVE
CVE-2026-95985
Severity
HIGH
CVSS
8.8
EPSS
0.14%

Original NVD Description

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.