Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
UnratedCVE-2026-89332 · Published Sep 11, 2026
Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-89332, where the Kiro agent could modify a workspace's settings file in an untrusted workspace in Kiro IDE. A specially crafted repository could use this to point the Kiro Powers registry URL, which Kiro fetches when the Powers panel is opened, at an external endpoint, sending potentially sensitive workspace data to that endpoint. Kiro presented the edit to the user for approval, showing the inserted data and the URL, but the file was already written to disk, so opening the Powers panel before responding to the prompt made the request anyway. Impacted versions: Kiro IDE < 0.8.135 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | Denial of service in the event stream header decoder in AWS SDK for Go v2 | Unrated | No fix yet |
| Sep 11 | XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin | Unrated | No fix yet |
| Sep 11 | Issue with projen - Path traversal and OS command injection | Unrated | No fix yet |
| Sep 10 | Server-side request forgery in the Session Manager port forwarding functionality in AWS... | Unrated | No fix yet |
| Sep 10 | Integer overflow in tensor buffer validation in Deep Java Library | Unrated | No fix yet |
| Sep 10 | Missing S3 bucket ownership verification in the AWS Security Agent plugin for... | Unrated | No fix yet |