CVE-2026-89332: Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened.
To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Kiro IDEto a version that resolves this vulnerability.Fixed in 0.8.135 - Operational
If you opened a project in an Amazon Kiro IDE version before 0.8.135, rotate any credentials that were present in that project.
Event History
Frequently Asked Questions
What user action is required for workspace data to be sent to an attacker-controlled endpoint?
A user must open crafted repository content in an affected Kiro IDE version, allowing the agent to modify the workspace settings file, and then open the Powers panel. Opening the Powers panel triggers the registry request to the attacker-controlled endpoint.
Who is exposed to this issue?
Developers using Kiro IDE before version 0.8.135 who open a repository containing crafted content are exposed. The issue can affect sensitive information present in the developer workspace.
What should be done if a potentially affected project was opened?
Upgrade Kiro IDE to version 0.8.135 or later. Rotate any credentials that were present in the project that was opened in an earlier version.