CVE-2026-95985

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-25: 109-25
Referenced assets1 URL
By indicator
Full discourse1 post
  • 星野ぽぽぽ / キュアクラウド@hoshino_popopo_

    Kiro IDE が 1.0.242 未満の人は、更新した方がいいよ 未信頼ワークスペースでエージェントを動かしたとき、グローバル設定を書き換えられる問題があるよ。 Kiro IDEを使ってる人は、バージョンをすぐ確認して即アップデート! CVE-2026-95985 https://aws.amazon.com/security/security-bulletins/2026-117-aws/

    00040246
    8.3K followersView on X

Explore more