Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95985— Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

Quick assessment

Affected
Amazon Kiro IDE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

亚马逊 Kiro IDE 版本 1.0.242 之前版本的文件写入工具可能存在漏洞,允许远程未经身份验证的攻击者向代理上下文注入特制指令。当用户在可疑仓库中以不受信任的工作空间运行代理时,发送任意消息可能导致代理修改自动加载的全局配置路径。 我们建议您升级至 Kiro IDE 版本 1.0.242 或更高版本。在早期版本中于不受信任工作空间运行代理的用户,还应检查全局 Kiro 配置目录(~/.kiro)中是否存在非自己创建的条目。

CVSS 8.8 · High EPSS 0.14% · P2

Affected Version Matrix 1

VendorProduct Version RangeStatus
Amazon Kiro IDE < 1.0.242 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95985

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
Source: CVE Program / CVE List V5
Vulnerability Description
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
从非可信控制范围包含功能例程
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Amazon Kiro IDE 0 ~ 1.0.242 -

II. Public POCs for CVE-2026-95985

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95985

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-95985 (1)

Vendor Pages for CVE-2026-95985 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-95985

No comments yet


Leave a comment