CVE-2026-9255 Details
Description
Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later.
A vulnerability in Kiro CLI prior to version 1.28.0 allows local attackers to execute arbitrary tools, including shell commands, without user approval. This is achieved by crafting content that is piped into Kiro CLI via standard input, taking advantage of missing input source validation in the tool authorization prompt.
Users are advised to upgrade to Kiro CLI version 1.28.0 or later. For those using versions prior to 1.28.0, it is recommended to run Kiro CLI with the --no-interactive flag when piping content from untrusted sources, as this will disable tool approval prompts and prevent the input from being treated as a confirmation response.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-035-aws/ | AMZN | Vendor Advisory |
| https://kiro.dev/changelog/cli/1-28/ | AMZN | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon kiro cli | < 1.28.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| May 22, 2026 | New CVE Received | AMZN |