CVE-2026-0830Disclosure(amazon / kiro_ide)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch amazon kiro_ide systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kiro_ide

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
kiro_ide

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 103-26
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • AWS Security Digest@AwsSecDigest
    Disclosure

    (CVE-2026-0830) AWS Kiro GitLab Helper RCE By: Dhiraj Mishra* Discover the crucial details behind a recent vulnerability in AWS's Kiro, an AI-powered IDE, that could compromise your security. The GitLab MR helper within Kiro was found to be susceptible to remote code execution (RCE) through unquoted shell command paths. By simply cloning a repository into a cleverly named folder, users could inadvertently execute arbitrary code. This issue was patched in version 0.6.18, but it serves as a stark reminder of the persistent risks associated with string interpolation into shell commands. 🔍 **Key Insights:** * 🚨 Vulnerability in Kiro's GitLab MR helper leading to potential security breaches. * 🛠️ The flaw involves unquoted paths in shell commands, a classic security pitfall. * 📈 Fixed in version 0.6.18, but underscores a recurring challenge in coding practices. Read Here: https://medium.com/@dhiraj_mishra/cve-2026-0830-aws-kiro-gitlab-helper-remote-code-execution-1f826469228d This was first mentioned in AWS Security Digest Issue #243: (https://awssecuritydigest.com/past-issues/aws-security-digest-243)

    Post summary

    CVE‑2026‑0830 exposes an RCE flaw in AWS Kiro’s GitLab MR helper through unquoted shell paths; the vulnerability was patched in 0.6.18, with no evidence of current exploitation or PoC.

    00011227
    1.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonkiro_ide---

Explore more