ACVE-2026-0432
Kiro IDE below 0.8.135, opened on an untrusted workspace, let the agent write workspace settings that could send sensitive workspace data to an external endpoint.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier CVE-2026-89332 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Fixed in 0.8.135 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Severity MODERATE; matches CNA | Confirmed | cveawg.mitre.org | 2026-09-24 |
In the wild
demonstrated · vendor
Description
What
AWS reported that the Kiro agent could modify a workspace settings file in an untrusted workspace and redirect the Kiro Powers registry. Opening the Powers panel could then send potentially sensitive workspace data externally, even though Kiro showed the edit for approval after it had already written the file.
Detection
Recorded from the AWS security bulletin. Not recreated in a lab.
Fix
Upgrade Kiro IDE to 0.8.135 or later and rotate credentials present in projects opened with an earlier version.
Fix
Upgrade Kiro IDE to 0.8.135 or later.
- Upgrade
harness:kiroto0.8.135. First version AWS identifies as addressed. Owner: operator