CVE-2026-95985: Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

Published Sep 24, 2026
·
Updated

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.

We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.

Affected Software

1 affected component
Amazon Kiro IDE<1.0.242

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kiro IDE to a version that resolves this vulnerability.

    Fixed in 1.0.242
  2. Operational

    If the agent was run in an untrusted workspace on an earlier version, review the global Kiro configuration directory (~/.kiro) for entries that were not created by the user.

Event History

Sep 24, 2026
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Users of Amazon Kiro IDE versions before 1.0.242 who run the agent in a crafted repository opened as an untrusted workspace are exposed. The attacker can be remote and unauthenticated, but user interaction is required.

2

What action triggers the malicious write?

After the agent is run in the crafted untrusted workspace, sending any message can cause it to modify auto-loaded global configuration paths.

3

Are default global configuration locations involved?

Yes. The affected writes can target auto-loaded global configuration paths, including the global Kiro configuration directory at ~/.kiro.

4

What should be done if the agent was used in an untrusted workspace before upgrading?

Upgrade to Kiro IDE 1.0.242 or later. Also review ~/.kiro for configuration entries that you did not create.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203