Impact
The flaw resides in the Kiro Powers component of Amazon Kiro IDE before version 0.8.135. Code from an untrusted control sphere is incorporated, allowing an attacker to craft repository files that, when a developer opens the a malicious workspace configuration. This configuration redirects the Kiro Powers registry request to an endpoint controlled by the attacker, resulting in the transmission of sensitive workspace data when the Powers panel is opened. This violates confidentiality and demonstrates improper input handling (CWE-201) and inadequate access control (CWE-829).
Affected Systems
Amazon Kiro IDE, provided by AWS, is affected for all installations running a version older than 0.8.135. Versions 0.8.135 and newer contain the fix.
Risk and Exploitability
The CVSS score is 6.7, indicating medium severity. The EPSS score is below 1%, implying a low overall risk of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a remote unauthenticated actor to host malicious repository content that a developer later opens within the IDE, enabling the agent to write the outbound configuration. Once the Powers panel is engaged, the redirected request sends the exposed workspace data to the attacker’s endpoint. Although the probability of exploitation is small, the impact if successful would be the unauthorized disclosure of proprietary or sensitive development data.
OpenCVE Enrichment