CVE-2026-89332: Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

Published Sep 11, 2026
·
Updated

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened.

To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.

Affected Software

1 affected component
Amazon Kiro IDE<0.8.135

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Amazon Kiro IDE to a version that resolves this vulnerability.

    Fixed in 0.8.135
  2. Operational

    If you opened a project in an Amazon Kiro IDE version before 0.8.135, rotate any credentials that were present in that project.

Event History

Sep 11, 2026
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What user action is required for workspace data to be sent to an attacker-controlled endpoint?

A user must open crafted repository content in an affected Kiro IDE version, allowing the agent to modify the workspace settings file, and then open the Powers panel. Opening the Powers panel triggers the registry request to the attacker-controlled endpoint.

2

Who is exposed to this issue?

Developers using Kiro IDE before version 0.8.135 who open a repository containing crafted content are exposed. The issue can affect sensitive information present in the developer workspace.

3

What should be done if a potentially affected project was opened?

Upgrade Kiro IDE to version 0.8.135 or later. Rotate any credentials that were present in the project that was opened in an earlier version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203