CVE-2026-4295 Details
Description
Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 0.8.0 or higher.
A vulnerability in Kiro IDE prior to version 0.8.0 on all supported platforms allows remote, unauthenticated threat actors to execute arbitrary code. This issue arises from improper trust boundary enforcement, which enables maliciously crafted project directory files to bypass workspace trust protections. When a local user opens the directory, the crafted files can execute unauthorized code.
Users should upgrade to Kiro IDE version 0.8.0 or higher. The latest version is available on the Kiro website. For those unable to upgrade immediately, it is advised to avoid opening untrusted project directories in Kiro IDE.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-009-AWS/ | AMZN | |
| https://kiro.dev/changelog/ide/0-8/ | AMZN |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | New CVE Received | AMZN |