Junglewise Threat Intelligence

CVE-2026-10591: Amazon Kiro IDE remote code execution via insufficient file write restrictions

CVE-2026-10591 · Severity: high · CVSS 8.8 · Published 2026-06-02

Technologies: Amazon AWS, Kiro IDE. Vendors: Amazon.

Executive brief

Kiro IDE is a development environment that allows developers to write and test code. This vulnerability allows an attacker to write files to execution-sensitive directories on the system, potentially enabling code execution, privilege escalation, or corruption of critical system files. An exploit could allow unauthorized modification of executable paths, leading to arbitrary code execution or complete system compromise.

Technical details

This vulnerability exists in Kiro IDE due to insufficient validation of file write operations, allowing files to be written to execution-sensitive paths such as system directories, application directories, or paths in the executable search path (e.g., PATH environment variable locations). The root cause is inadequate access control checks before permitting file write operations. An attacker with local or network access to the IDE (depending on deployment) can write malicious executable files to critical directories, resulting in arbitrary code execution when those files are invoked. This could enable privilege escalation if the IDE runs with elevated privileges. Patches or fixes have not been specified in the available advisory details.

Affected products

  • Kiro IDE

Timeline

  • 2026-09-22: disclosed

References

Related threats