{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0432",
  "aliases": [
    "CVE-2026-89332"
  ],
  "published": "2026-09-11T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Kiro IDE below 0.8.135, opened on an untrusted workspace, let the agent write workspace settings that could send sensitive workspace data to an external endpoint.",
  "details": "## What\n\nAWS reported that the Kiro agent could modify a workspace settings file in an untrusted workspace and redirect the Kiro Powers registry. Opening the Powers panel could then send potentially sensitive workspace data externally, even though Kiro showed the edit for approval after it had already written the file.\n\n## Detection\n\nRecorded from the AWS security bulletin. Not recreated in a lab.\n\n## Fix\n\nUpgrade Kiro IDE to 0.8.135 or later and rotate credentials present in projects opened with an earlier version.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "kiro"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.8.135"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://aws.amazon.com/security/security-bulletins/2026-111-aws/"
    }
  ],
  "database_specific": {
    "severity": "MODERATE",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "config-file-injection",
        "data-exfiltration"
      ],
      "cwe": [
        "CWE-15",
        "CWE-693"
      ],
      "cveBoundary": "cve-aliased",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://aws.amazon.com/security/security-bulletins/2026-111-aws/",
            "type": "vendor"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Upgrade Kiro IDE to 0.8.135 or later.",
        "actions": [
          {
            "type": "upgrade",
            "target": "harness:kiro",
            "to": "0.8.135",
            "why": "First version AWS identifies as addressed.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Kiro IDE below 0.8.135",
          "any": false,
          "status": "confirmed",
          "source": "https://aws.amazon.com/security/security-bulletins/2026-111-aws/"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any coding task opened in an untrusted workspace",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Workspace settings and the Kiro Powers registry",
          "status": "confirmed",
          "source": "https://aws.amazon.com/security/security-bulletins/2026-111-aws/"
        },
        "approval": {
          "value": "A confirmation prompt was shown, but the file had already been written before the user answered",
          "mode": "auto-approve",
          "status": "confirmed",
          "source": "https://aws.amazon.com/security/security-bulletins/2026-111-aws/"
        },
        "inputControl": "repo-author",
        "agentAction": "The agent writes workspace settings that redirect a later Powers request.",
        "harm": "data-exfiltration",
        "divergence": "none",
        "reach": {
          "value": "Sensitive data in the opened workspace",
          "kinds": [
            "project-files",
            "private-repositories"
          ],
          "status": "confirmed",
          "source": "https://aws.amazon.com/security/security-bulletins/2026-111-aws/"
        }
      },
      "claims": [
        {
          "kind": "identifier",
          "statement": "Identifier CVE-2026-89332",
          "value": "CVE-2026-89332",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-89332",
          "result": "match",
          "observed": "CVE.org: PUBLISHED",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:22Z"
        },
        {
          "kind": "fixed-version",
          "statement": "Fixed in 0.8.135",
          "value": "0.8.135",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-89332",
          "result": "match",
          "observed": "CVE.org structured: lessThan 0.8.135; affected-version 0; CVE.org description: fixed 0.8.135",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:22Z"
        },
        {
          "kind": "severity",
          "statement": "Severity MODERATE; matches CNA",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-89332",
          "observed": "CNA: MODERATE 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N); CNA: MODERATE 6.7 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)",
          "result": "match",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:22Z"
        }
      ],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
