{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-95985","assignerOrgId":"ff89ba41-3aa1-4d27-914a-91399e9639e5","state":"PUBLISHED","assignerShortName":"AMZN","dateReserved":"2026-09-22T17:39:51.695Z","datePublished":"2026-09-24T17:07:47.783Z","dateUpdated":"2026-09-24T17:24:09.224Z"},"containers":{"cna":{"providerMetadata":{"orgId":"ff89ba41-3aa1-4d27-914a-91399e9639e5","shortName":"AMZN","dateUpdated":"2026-09-24T17:13:36.527Z"},"title":"Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-829","description":"CWE-829 Inclusion of functionality from untrusted control sphere","type":"CWE"}]},{"descriptions":[{"lang":"en","cweId":"CWE-349","description":"CWE-349 Acceptance of extraneous untrusted data with trusted data","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-549","descriptions":[{"lang":"en","value":"CAPEC-549 Local Execution of Code"}]}],"affected":[{"vendor":"Amazon","product":"Kiro IDE","platforms":["MacOS","Windows","Linux"],"versions":[{"status":"affected","version":"0","lessThan":"1.0.242","versionType":"custom"}],"defaultStatus":"unaffected"}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:amazon:kiro_ide:*:*:macos:*:*:*:*:*","versionStartIncluding":"0","versionEndExcluding":"1.0.242"},{"vulnerable":true,"criteria":"cpe:2.3:a:amazon:kiro_ide:*:*:windows:*:*:*:*:*","versionStartIncluding":"0","versionEndExcluding":"1.0.242"},{"vulnerable":true,"criteria":"cpe:2.3:a:amazon:kiro_ide:*:*:linux:*:*:*:*:*","versionStartIncluding":"0","versionEndExcluding":"1.0.242"}]}]}],"descriptions":[{"lang":"en","value":"The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.\n\n\n\nWe recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.</p><p>We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (<code>~/.kiro)</code> for entries they did not create.</p>"}]}],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-117-aws/","tags":["vendor-advisory"]},{"url":"https://kiro.dev/changelog/ide/1-0-242/","tags":["release-notes","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":8.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":8.6,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-24T17:23:54.377945Z","id":"CVE-2026-95985","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-24T17:24:09.224Z"}}]}}