CVE-2026-5429Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should upgrade to version 0.8.140.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-03); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-03: 1Mentions · 2026-04-16: 1Mentions · 2026-04-20: 1Mentions · 2026-06-09: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-20: 1Technical Details · 2026-06-09: 104-0304-1604-2006-09
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-031
Disclosure1
2026-04-161
General1
2026-04-201
Disclosure1
2026-06-091
Disclosure1
Full discourse4 posts
  • Dhiraj@RandomDhiraj
    General

    Part-2, Here is the write-up for my recent work RCE in AWS Kiro IDE (CVE-2026–5429). https://medium.com/@dhiraj_mishra/part-2-cve-2026-5429-aws-kiro-webview-xss-to-remote-code-execution-b1099cb7c945 #infosec #AI https://t.co/1q90WYNWKH

    Post summary

    The tweet points to a Medium article describing an RCE vulnerability (CVE-2026–5429) in AWS Kiro IDE, but it contains no additional technical details, proof‑of‑concept code, patches, or evidence of active exploitation.

    02086731
    3.4K followersView on X
  • AWS Security Digest@AwsSecDigest
    Disclosure

    🛎️ AWS Security Digest 257 is out! 1️⃣ CVE-2026-5429 AWS Kiro WebView XSS to Remote Code Execution by Dhiraj Mishra 2️⃣ The Invisible Footprint: How Anonymous S3 Requests Evade AWS Logging by Maya Parizer https://awssecuritydigest.com/past-issues/aws-security-digest-257

    Post summary

    AWS Security Digest 257 announces the discovery of CVE-2026-5429, describing an XSS vulnerability in AWS Kiro WebView that enables remote code execution; no PoC, exploit, or patch information is provided.

    01052312
    1.7K followersView on X
  • AWS Security Digest@AwsSecDigest
    Disclosure

    Part 2 — CVE-2026-5429: Kiro WebView XSS → RCE Dhiraj Mishra Kiro inserts workbench.colorTheme into an inline script with no escaping and no Content Security Policy, so a malicious theme extension checked into a repo’s .vscode/ folder runs arbitrary JS as soon as the project opens. The webview also exposes a subprocess message handler that shells out, allowing that theme-based XSS to escalate to full command execution as the developer. This is Dhiraj’s second Kiro-to-RCE after the unquoted-workspace-path injection—workspace settings/extensions are a repeatable attack surface. 🔍 Technical chain: unescaped inline theme + no CSP → webview XSS → exposed subprocess handler → shell exec as user 🔐 Key insight: a crafted theme checked into a repo can immediately compromise a developer; treat workspace metadata/extensions as high-risk input and add CSP, escaping, and stricter message-handler controls. First reported in AWS Security Digest Issue #257: https://awssecuritydigest.com/past-issues/aws-security-digest-257 Read here: https://medium.com/@dhiraj_mishra/part-2-cve-2026-5429-aws-kiro-webview-xss-to-remote-code-execution-b1099cb7c945

    Post summary

    The notice reports a new Kiro WebView vulnerability (CVE‑2026‑5429) with detailed exploitation chain and mitigation suggestions, but no PoC, active exploitation, or patch is provided.

    00000122
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5429 Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitr… https://www.cve.org/CVERecord?id=CVE-2026-5429

    Post summary

    The post briefly discloses CVE‑2026‑5429, noting unsanitized input in Kiro IDE that permits remote unauthenticated code execution, without providing exploit details, patches, or evidence of active exploitation.

    00000161
    56.9K followersView on X

Explore more