Back to vendor advisories
AWS Security BulletinsCVE-2026-95985

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

Bulletin ID: 2026-117-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 10:00 AM PDT Description: Kiro is an agentic IDE that users install on their desktop. We identified CVE-2026-95985. The file write tool in Kiro IDE before version 1.0.242 might allow remote unauthenticated actors to execute arbitrary commands and to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. Impacted versions: < 1.0.242 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. View article

Not listedCVSS not listedNot listed severity
Scope

What the vendor says is affected

The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.

Timeline

When this advisory changed

  1. Published by AWS

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory