The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.
We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create. | |
| Title | Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces | |
| First Time appeared |
Amazon
Amazon kiro Ide |
|
| Weaknesses | CWE-349 CWE-829 |
|
| CPEs | cpe:2.3:a:amazon:kiro_ide:*:*:linux:*:*:*:*:* cpe:2.3:a:amazon:kiro_ide:*:*:macos:*:*:*:*:* cpe:2.3:a:amazon:kiro_ide:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Amazon
Amazon kiro Ide |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-24T17:24:09.224Z
Reserved: 2026-09-22T17:39:51.695Z
Link: CVE-2026-95985
No data.
No data.
No data.
OpenCVE Enrichment
No data.