Executive brief
Kiro IDE is a development environment that uses AI agents to assist with software engineering tasks. A security flaw allows a malicious actor to execute unauthorized code on a developer's machine if the developer opens a specially crafted workspace and chooses to trust it. This could lead to a full system compromise, data theft, or unauthorized access to source code.
Technical details
A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in the Kiro Agent webview component of Kiro IDE due to improper neutralization of input during web page generation. An attacker can exploit this by crafting a workspace with a malicious color theme name. When a local user opens this workspace and accepts the 'trust workspace' prompt, the unsanitized theme name is processed by the webview, leading to arbitrary code execution. The vulnerability is resolved in version 0.8.140.
Affected products
- AWS Kiro IDE before 0.8.140
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory
- 2026-04-02: patched: Fixed in version 0.8.140