Junglewise Threat Intelligence

CVE-2026-0830: AWS Kiro IDE command injection in GitLab Merge Request Helper

CVE-2026-0830 · Severity: high · Published 2026-01-09

Technologies: AWS Kiro IDE, Amazon AWS. Vendors: AWS, Amazon.

Executive brief

Kiro is an AI-powered development environment installed on user desktops. A security flaw allows an attacker to execute unauthorized commands on a user's computer if the user is tricked into opening a specially crafted project workspace. This could lead to full system compromise, data theft, or the installation of malware on the developer's workstation.

Technical details

A command injection vulnerability exists in the Kiro GitLab Merge Request Helper component of Kiro IDE prior to version 0.6.18. The flaw is triggered when the application fails to properly sanitize folder names within a workspace, allowing shell commands embedded in those names to be executed during workspace initialization or processing. An attacker must convince a user to open a malicious workspace (local attack vector requiring user interaction). Successful exploitation grants the attacker the ability to execute arbitrary commands with the privileges of the IDE user. The issue is resolved in version 0.6.18.

Affected products

  • AWS Kiro IDE < 0.6.18

Timeline

  • 2026-01-09: disclosed
  • 2026-01-09: patched: Fixed in version 0.6.18

References

Related threats