亚马逊 Kiro IDE 版本 1.0.242 之前版本的文件写入工具可能存在漏洞,允许远程未经身份验证的攻击者向代理上下文注入特制指令。当用户在可疑仓库中以不受信任的工作空间运行代理时,发送任意消息可能导致代理修改自动加载的全局配置路径。 我们建议您升级至 Kiro IDE 版本 1.0.242 或更高版本。在早期版本中于不受信任工作空间运行代理的用户,还应检查全局 Kiro 配置目录(~/.kiro)中是否存在非自己创建的条目。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet