CVE-2026-5429: Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme
Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace when prompted.
To remediate this issue, users should upgrade to version 0.8.140.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiro IDEto a version that resolves this vulnerability.Fixed in 0.8.140 - Compensating control
When prompted to trust the workspace, only trust workspaces you control or that you have verified, since exploitation requires a local user to open (and trust) the workspace.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5429?
CVE-2026-5429 has been classified as a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2026-5429?
To fix CVE-2026-5429, update Kiro IDE to version 0.8.140 or later to eliminate the vulnerability.
What type of vulnerability is CVE-2026-5429?
CVE-2026-5429 is classified as a Cross-Site Scripting (XSS) vulnerability affecting the Kiro Agent webview.
Who is affected by CVE-2026-5429?
CVE-2026-5429 affects users of Kiro IDE versions prior to 0.8.140.
Can CVE-2026-5429 be exploited remotely?
Yes, CVE-2026-5429 can be exploited remotely by unauthenticated attackers.