CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
Bulletin ID: 2026-117-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/24/2026 10:00 AM PDT
Description:
Kiro is an agentic IDE that users install on their desktop. We identified CVE-2026-95985. The file write tool in Kiro IDE before version 1.0.242 might allow remote unauthenticated actors to execute arbitrary commands and to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.
Impacted versions: < 1.0.242
Resolution:
This issue has been addressed in Kiro IDE version 1.0.242. We recommend upgrading to the latest version. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro on macOS and Linux, %USERPROFILE%\.kiro on Windows) for entries they did not create.
Workarounds:
None.
References:
Acknowledgement:
We would like to thank Dinh Ngoc Dung for collaborating on this issue through the coordinated disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.