CVE-2026-95985: Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.
We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiro IDEto a version that resolves this vulnerability.Fixed in 1.0.242 - Operational
If the agent was run in an untrusted workspace on an earlier version, review the global Kiro configuration directory (~/.kiro) for entries that were not created by the user.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users of Amazon Kiro IDE versions before 1.0.242 who run the agent in a crafted repository opened as an untrusted workspace are exposed. The attacker can be remote and unauthenticated, but user interaction is required.
What action triggers the malicious write?
After the agent is run in the crafted untrusted workspace, sending any message can cause it to modify auto-loaded global configuration paths.
Are default global configuration locations involved?
Yes. The affected writes can target auto-loaded global configuration paths, including the global Kiro configuration directory at ~/.kiro.
What should be done if the agent was used in an untrusted workspace before upgrading?
Upgrade to Kiro IDE 1.0.242 or later. Also review ~/.kiro for configuration entries that you did not create.