Impact
Insufficient access control in the file write tool in Amazon Kiro IDE before version 0.11 allows a remote unauthenticated actor to instruct the IDE to write to execution‑sensitive paths such as .vscode/tasks.json. The crafted write causes the IDE to auto‑execute these files when a folder is opened, giving the attacker the ability to run arbitrary commands on the host. This flaw is classified as CWE‑732, Incorrect Permission Assignment, and can lead to complete system compromise if exploited.
Affected Systems
All versions of AWS Kiro IDE released prior to 0.11 contain the flaw. The vulnerability applies to the Amazon Kiro IDE product, which is distributed by AWS.
Risk and Exploitability
The CVSS score of 8.6 indicates a high‑severity vulnerability with potential for heavy impact. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is currently no publicly known exploitation case, but the lack of EPSS data does not reduce the inherent risk. The likely attack vector is inferred from the description: a remote attacker can send crafted write instructions to the vulnerable file write tool, causing the IDE to modify execution‑sensitive paths and trigger auto‑execution of malicious commands.
OpenCVE Enrichment