CVE-2026-4295: Arbitrary code execution via crafted project files in Kiro IDE
Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory.
To remediate this issue, users should upgrade to version 0.8.0 or higher.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4295?
CVE-2026-4295 has a high severity rating as it allows for arbitrary code execution.
How do I fix CVE-2026-4295?
To fix CVE-2026-4295, update Kiro IDE to version 0.8.0 or later.
What types of systems are affected by CVE-2026-4295?
CVE-2026-4295 affects all supported platforms running Kiro IDE versions prior to 0.8.0.
Who can exploit CVE-2026-4295?
CVE-2026-4295 can be exploited by remote unauthenticated threat actors using malicious project directory files.
What is the main risk associated with CVE-2026-4295?
The main risk associated with CVE-2026-4295 is potentially allowing arbitrary code execution on vulnerable systems.