CVE-2026-0830: Command Injection in Kiro GitLab Merge Request Helper
Published Jan 9, 2026
·Updated
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces.
To mitigate, users should update to the latest version.
Affected Software
2 affected components
Kiro Kiro IDE<0.6.18
Amazon Kiro IDE<0.6.18
Event History
Jan 9, 2026
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0830?
CVE-2026-0830 is classified as a critical vulnerability due to the potential for arbitrary command injection.
2
How do I fix CVE-2026-0830?
To fix CVE-2026-0830, update your Kiro IDE to version 0.6.18 or later.
3
What software is affected by CVE-2026-0830?
CVE-2026-0830 affects Kiro IDE versions prior to 0.6.18.
4
What types of attacks are possible due to CVE-2026-0830?
CVE-2026-0830 allows for arbitrary command injection through specially crafted workspace folder names.
5
How can I identify if I'm vulnerable to CVE-2026-0830?
If you are using a version of Kiro IDE below 0.6.18, you are vulnerable to CVE-2026-0830.