8.4
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces.
To mitigate, users should update to the latest version.
To mitigate, users should update to the latest version.
Basic Information
ID
CVE-2026-0830
Source
AMZN
Published
Jan 9, 2026 at 21:10
Modified
Jan 9, 2026 at 21:18
Affected Product
Vendor
AWS
Product
Kiro IDE
Affected Versions
AWS Kiro IDE 0