
Kiro IDE が 1.0.242 未満の人は、更新した方がいいよ 未信頼ワークスペースでエージェントを動かしたとき、グローバル設定を書き換えられる問題があるよ。 Kiro IDEを使ってる人は、バージョンをすぐ確認して即アップデート! CVE-2026-95985 https://aws.amazon.com/security/security-bulletins/2026-117-aws/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

Kiro IDE が 1.0.242 未満の人は、更新した方がいいよ 未信頼ワークスペースでエージェントを動かしたとき、グローバル設定を書き換えられる問題があるよ。 Kiro IDEを使ってる人は、バージョンをすぐ確認して即アップデート! CVE-2026-95985 https://aws.amazon.com/security/security-bulletins/2026-117-aws/