CVE-2026-10591

HIGH8.8Publicada el 2 de junio de 2026

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.

Puntuación CVSS8.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Tipo de debilidad (CWE)CWE-732
Fabricantesamazon

Productos afectados

FabricantesProdottoVersioni
amazonkiro ide< 0.11

Artículos relacionados

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de datos CVE