Executive brief
Kiro IDE, a development environment tool, stores authentication tokens in a cache file with overly permissive access controls. An attacker with local access to the affected system could read these cached tokens to impersonate legitimate users or gain unauthorized access to protected resources and accounts.
Technical details
CVE-2026-11931 is an insecure file permissions vulnerability in Kiro IDE where authentication tokens are cached in a file with overly permissive access controls. The vulnerable component is the authentication token cache mechanism. An attacker with local system access (e.g., through a shared system, container, or VM escape) can read the cache file to extract authentication tokens in plaintext or weakly protected form. The attack requires local file system access and does not require user interaction or network access. A successful exploit allows the attacker to obtain valid authentication credentials and use them to impersonate the legitimate user. Patches or configuration guidance to restrict file permissions should be available from the vendor.
Affected products
- Kiro IDE
Timeline
- 2026-09-22: disclosed