Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open.
To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later. | |
| Title | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | |
| First Time appeared |
Aws
Aws kiro Ide |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:aws:kiro_ide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws kiro Ide |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published: 2026-06-02T15:34:40.106Z
Updated: 2026-06-02T16:08:38.713Z
Reserved: 2026-06-01T20:46:32.966Z
Link: CVE-2026-10591
Updated: 2026-06-02T16:08:34.472Z
Status : Awaiting Analysis
Published: 2026-06-02T16:16:34.647
Modified: 2026-06-02T17:18:50.850
Link: CVE-2026-10591
No data.