Skip to content
AWSAWS-2026-037

Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths

High8.8CVE-2026-10591 · Published Sep 22, 2026

Bulletin ID:  2026-037-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/02/2026 08:45 AM PDT Description: Kiro is an agentic IDE users install on their desktop. We identified CVE-2026-10591 . Insufficient access control restrictions in the file write tool in Kiro IDE prior to version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. Impacted versions:   Resolution: This issue has been addressed in Kiro IDE version 0.11 . We recommend upgrading to the latest version. Workarounds: No workaround available. References: CVE-2026-10591 Acknowledgement: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Sep 26Severity: Unrated to High
Details and references

Bulletin ID:  2026-037-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/02/2026 08:45 AM PDT Description: Kiro is an agentic IDE users install on their desktop. We identified CVE-2026-10591 . Insufficient access control restrictions in the file write tool in Kiro IDE prior to version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. Impacted versions:   Resolution: This issue has been addressed in Kiro IDE version 0.11 . We recommend upgrading to the latest version. Workarounds: No workaround available. References: CVE-2026-10591 Acknowledgement: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-037-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths Bulletin ID:  2026-037-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/02/2026 08:45 AM PDT Description: Kiro is an agentic IDE users install on their desktop. We identified CVE-2026-10591 . Insufficient access control restrictions in the file write tool in Kiro IDE prior to version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. Impacted versions:   Resolution: This issue has been addressed in Kiro IDE version 0.11 . We recommend upgrading to the latest version. Workarounds: No workaround available. References: CVE-2026-10591 Acknowledgement: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email  aws-security@amazon.com  with any security questions or concerns.   {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.", "copyrightText": "© 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved.", "items": [ { "name": "Learn", "linkURL": "", "items": [ { "heading": "What Is AWS?", "linkURL": "/what-is-aws/?nc1=f_cc" }, { "heading": "What Is Cloud Computing?", "linkURL": "/what-is-cloud-computing/?nc1=f_cc" }, { "heading": "What Is Agentic AI?", "linkURL": "/what-is/agentic-ai/?nc1=f_cc" }, { "heading": "Cloud Computing Concepts Hub", "linkURL": "/what-is/?nc1=f_cc" }, { "heading": "AWS Cloud Security", "linkURL": "/security/?nc1=f_cc"

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
NVD

More AWS advisories

All AWS
Advisory
Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible...
High8.0Sep 22
HTTPS Fallback to HTTP in Graph Explorer
Medium5.9Sep 22
Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import
Critical9.0Sep 22
Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Critical9.8Sep 22
Authenticated SQL injection in the metrics-service retention policy subsystem of...
High8.1Sep 22
Excessive memory allocation in s2n-quic
Medium5.3Sep 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.