{"schema_version":1,"title":"AWS Kiro IDE vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 7 vulnerabilities in AWS Kiro IDE: 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-89332, was published on 11 September 2026.","url":"https://junglewise.ai/threats/technologies/kiro-ide","json_url":"https://junglewise.ai/threats/technologies/kiro-ide.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/kiro-ide","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":7,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":2,"last_365_days":7},"latest":[{"cve":"CVE-2026-89332","cvss":5.5,"epss":0.0018,"slug":"cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written","title":"Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow","severity":"high","exploited":false,"published_at":"2026-09-11T20:19:23.67+00:00","url":"https://junglewise.ai/threats/cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written"},{"cve":"CVE-2026-18656","cvss":7.8,"epss":0.0022,"slug":"cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory","title":"An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbi","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:50.41+00:00","url":"https://junglewise.ai/threats/cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory"},{"cve":"CVE-2026-11931","cvss":5.5,"slug":"cve-2026-11931-amazon-kiro-ide-incorrect-permissions-in-authentication-token","title":"Amazon Kiro IDE incorrect permissions in authentication token cache","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:25.29+00:00","url":"https://junglewise.ai/threats/cve-2026-11931-amazon-kiro-ide-incorrect-permissions-in-authentication-token"},{"cve":"CVE-2026-10591","cvss":8.8,"slug":"cve-2026-10591-amazon-kiro-ide-remote-code-execution-via-insufficient-file-write","title":"Amazon Kiro IDE remote code execution via insufficient file write restrictions","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:34.647+00:00","url":"https://junglewise.ai/threats/cve-2026-10591-amazon-kiro-ide-remote-code-execution-via-insufficient-file-write"},{"cve":"CVE-2026-5429","cvss":7.8,"epss":0.0016,"slug":"cve-2026-5429-aws-kiro-ide-arbitrary-code-execution-in-kiro-agent-webview","title":"AWS Kiro IDE arbitrary code execution in Kiro Agent webview","severity":"high","exploited":false,"published_at":"2026-04-02T19:21:37.083+00:00","url":"https://junglewise.ai/threats/cve-2026-5429-aws-kiro-ide-arbitrary-code-execution-in-kiro-agent-webview"},{"cve":"CVE-2026-4295","slug":"cve-2026-4295-aws-kiro-ide-arbitrary-code-execution-via-crafted-project-files","title":"AWS Kiro IDE arbitrary code execution via crafted project files","severity":"high","exploited":false,"published_at":"2026-03-17T19:20:39+00:00","url":"https://junglewise.ai/threats/cve-2026-4295-aws-kiro-ide-arbitrary-code-execution-via-crafted-project-files"},{"cve":"CVE-2026-0830","slug":"cve-2026-0830-aws-kiro-ide-command-injection-in-gitlab-merge-request-helper","title":"AWS Kiro IDE command injection in GitLab Merge Request Helper","severity":"high","exploited":false,"published_at":"2026-01-09T21:25:49+00:00","url":"https://junglewise.ai/threats/cve-2026-0830-aws-kiro-ide-command-injection-in-gitlab-merge-request-helper"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"AWS Cloud Development Kit","slug":"cdk","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/cdk"},{"name":"AWS-LC","slug":"lc","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/lc"},{"name":"Aws-Lc-Sys","slug":"aws-lc-sys","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/aws-lc-sys"}],"technology":{"hub":true,"name":"AWS Kiro IDE","slug":"kiro-ide","vendor":{"name":"AWS","slug":"aws","url":"https://junglewise.ai/threats/vendors/aws"},"aliases":[],"category":"ide","url":"https://junglewise.ai/threats/technologies/kiro-ide"},"most_severe":[{"cve":"CVE-2026-10591","cvss":8.8,"slug":"cve-2026-10591-amazon-kiro-ide-remote-code-execution-via-insufficient-file-write","title":"Amazon Kiro IDE remote code execution via insufficient file write restrictions","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:34.647+00:00","url":"https://junglewise.ai/threats/cve-2026-10591-amazon-kiro-ide-remote-code-execution-via-insufficient-file-write"},{"cve":"CVE-2026-18656","cvss":7.8,"epss":0.0022,"slug":"cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory","title":"An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbi","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:50.41+00:00","url":"https://junglewise.ai/threats/cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory"},{"cve":"CVE-2026-5429","cvss":7.8,"epss":0.0016,"slug":"cve-2026-5429-aws-kiro-ide-arbitrary-code-execution-in-kiro-agent-webview","title":"AWS Kiro IDE arbitrary code execution in Kiro Agent webview","severity":"high","exploited":false,"published_at":"2026-04-02T19:21:37.083+00:00","url":"https://junglewise.ai/threats/cve-2026-5429-aws-kiro-ide-arbitrary-code-execution-in-kiro-agent-webview"},{"cve":"CVE-2026-89332","cvss":5.5,"epss":0.0018,"slug":"cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written","title":"Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow","severity":"high","exploited":false,"published_at":"2026-09-11T20:19:23.67+00:00","url":"https://junglewise.ai/threats/cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written"},{"cve":"CVE-2026-11931","cvss":5.5,"slug":"cve-2026-11931-amazon-kiro-ide-incorrect-permissions-in-authentication-token","title":"Amazon Kiro IDE incorrect permissions in authentication token cache","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:25.29+00:00","url":"https://junglewise.ai/threats/cve-2026-11931-amazon-kiro-ide-incorrect-permissions-in-authentication-token"},{"cve":"CVE-2026-4295","slug":"cve-2026-4295-aws-kiro-ide-arbitrary-code-execution-via-crafted-project-files","title":"AWS Kiro IDE arbitrary code execution via crafted project files","severity":"high","exploited":false,"published_at":"2026-03-17T19:20:39+00:00","url":"https://junglewise.ai/threats/cve-2026-4295-aws-kiro-ide-arbitrary-code-execution-via-crafted-project-files"},{"cve":"CVE-2026-0830","slug":"cve-2026-0830-aws-kiro-ide-command-injection-in-gitlab-merge-request-helper","title":"AWS Kiro IDE command injection in GitLab Merge Request Helper","severity":"high","exploited":false,"published_at":"2026-01-09T21:25:49+00:00","url":"https://junglewise.ai/threats/cve-2026-0830-aws-kiro-ide-command-injection-in-gitlab-merge-request-helper"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}