Description
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open.
To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.
To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later. | |
| Title | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | |
| First Time appeared |
Aws
Aws kiro Ide |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:aws:kiro_ide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws kiro Ide |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-06-02T15:34:40.106Z
Reserved: 2026-06-01T20:46:32.966Z
Link: CVE-2026-10591
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses