216.73.216.36

CVE-2026-10591

· Published 02/06/2026 16:16 · Modified 02/06/2026 17:18

Labels: CVE-2026-10591 2026-06-02CVE-2026-10591CWE-732ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
02/06/2026 16:16
Modified
02/06/2026 17:18
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
amazon / kiro ide cpe:2.3:a:amazon:kiro_ide:<0.11:*:*:*:*:*:*:*

References