Executive brief
Kiro IDE is an AI-powered development environment used for building software. A security flaw allows an attacker to execute malicious code on a developer's computer if the developer is tricked into opening a specially crafted project folder. This could lead to the theft of sensitive source code, credentials, or full control over the developer's workstation.
Technical details
A vulnerability exists in Kiro IDE versions prior to 0.8.0 due to improper trust boundary enforcement when loading project files. An attacker can achieve arbitrary code execution by convincing a user to open a maliciously crafted project directory within the IDE. This is a local attack vector requiring user interaction (opening the directory). The root cause involves the IDE executing or processing untrusted configuration or project files without sufficient isolation or validation. The issue is resolved in version 0.8.0.
Affected products
- AWS Kiro IDE < 0.8.0
Timeline
- 2026-03-17: disclosed
- 2026-03-17: patched: Fixed in version 0.8.0