Amazon

Kiro Ide

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 24.09.2026 17:07:47
  • Zuletzt bearbeitet 24.09.2026 19:36:39

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending an...

  • EPSS 0.16%
  • Veröffentlicht 11.09.2026 19:03:37
  • Zuletzt bearbeitet 16.09.2026 13:49:23

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repositor...

  • EPSS 0.16%
  • Veröffentlicht 04.08.2026 20:16:50
  • Zuletzt bearbeitet 18.08.2026 14:43:38

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust ...

Medienbericht
  • EPSS 0.66%
  • Veröffentlicht 02.06.2026 15:34:40
  • Zuletzt bearbeitet 22.07.2026 19:10:00

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (s...

  • EPSS 1.3%
  • Veröffentlicht 09.01.2026 21:16:14
  • Zuletzt bearbeitet 28.04.2026 17:41:17

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update t...