Skip to content
amazonCVE-2026-95985

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context.

High8.6CVE-2026-95985 · Published Sep 24, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Kiro IDE
Vendor
< 1.0.2421.0.242
Details and references

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
no source yet
Weakness
CWE-349, CWE-829

More amazon advisories

All
DateAdvisory
Aug 18Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.
CVE-2026-75936High8.7fixed in Amazon Ion Java 1.12.0
Aug 4An uncontrolled search path element in Kiro CLI before version 2.10.
CVE-2026-18657High8.5fixed in Kiro CLI 2.10.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.