PT-2026-45768 · Amazon · Kiro Ide
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon Kiro IDE versions prior to 0.11
Description
Insufficient access control restrictions in the file write tool allow remote unauthenticated actors to execute arbitrary commands. This is achieved by using crafted instructions to write to execution-sensitive paths, such as ".vscode/tasks.json", which enables auto-execution when a folder is opened.
Recommendations
Upgrade to version 0.11 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiro Ide