Description
Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened.



To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.
Published: 2026-09-11
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exfiltration
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the Kiro Powers component of Amazon Kiro IDE before version 0.8.135. Code from an untrusted control sphere is incorporated, allowing an attacker to craft repository files that, when a developer opens the a malicious workspace configuration. This configuration redirects the Kiro Powers registry request to an endpoint controlled by the attacker, resulting in the transmission of sensitive workspace data when the Powers panel is opened. This violates confidentiality and demonstrates improper input handling (CWE-201) and inadequate access control (CWE-829).

Affected Systems

Amazon Kiro IDE, provided by AWS, is affected for all installations running a version older than 0.8.135. Versions 0.8.135 and newer contain the fix.

Risk and Exploitability

The CVSS score is 6.7, indicating medium severity. The EPSS score is below 1%, implying a low overall risk of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a remote unauthenticated actor to host malicious repository content that a developer later opens within the IDE, enabling the agent to write the outbound configuration. Once the Powers panel is engaged, the redirected request sends the exposed workspace data to the attacker’s endpoint. Although the probability of exploitation is small, the impact if successful would be the unauthorized disclosure of proprietary or sensitive development data.

Generated by OpenCVE AI on September 21, 2026 at 03:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Kiro IDE version 0.8.135 or later.
  • If a project was opened with an earlier version, rotate any credentials stored in that project.
  • Review repository contents for unexpected workspace configuration files and remove or neutralize any malicious redirects or payloads.

Generated by OpenCVE AI on September 21, 2026 at 03:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon kiro Ide
CPEs cpe:2.3:a:amazon:kiro_ide:*:*:*:*:*:*:*:*
Vendors & Products Amazon
Amazon kiro Ide

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened. To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.
Title Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
First Time appeared Aws
Aws kiro Ide
Weaknesses CWE-201
CWE-829
CPEs cpe:2.3:a:aws:kiro_ide:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws kiro Ide
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-11T19:47:58.681Z

Reserved: 2026-09-11T15:47:22.409Z

Link: CVE-2026-89332

cve-icon Vulnrichment

Updated: 2026-09-11T19:34:49.475Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T20:19:23.670

Modified: 2026-09-16T13:49:23.337

Link: CVE-2026-89332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:30:08Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere