CVE-2026-95985
8.8 HIGHPublished 2026-09-24 · Updated 2026-09-24
AI risk analysis
- Summary
- This vulnerability allows remote unauthenticated actors to inject malicious instructions into the agent's context, potentially leading to unauthorized modifications of global configurations.
- Exploitability
- Exploitation requires running the agent in an untrusted workspace with a crafted repository, making it moderately difficult.
- Blast radius
- If exploited, the impact could be high, as it could lead to unauthorized changes in global configurations affecting the entire system.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Kiro IDE version 1.0.242 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-349, CWE-829
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-66902PoC
- HIGHCVE-2025-51457
- CRITICALCVE-2025-66455PoC
- HIGHCVE-2026-100520PoC
- HIGHCVE-2026-100552PoC
- HIGHCVE-2026-100586PoC
- HIGHCVE-2026-100587PoC
- CRITICALCVE-2026-100715PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.