Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cymulate

#28761of 53,622
8.8Total CVSS
Vulnerabilities · 1
PT-2026-45768
8.8
2026-06-02
Amazon · Kiro Ide · CVE-2026-10591
**Name of the Vulnerable Software and Affected Versions** Amazon Kiro IDE versions prior to 0.11 **Description** Insufficient access control restrictions in the file write tool allow remote unauthenticated actors to execute arbitrary commands. This is achieved by using crafted instructions to write to execution-sensitive paths, such as ".vscode/tasks.json", which enables auto-execution when a folder is opened. **Recommendations** Upgrade to version 0.11 or later.