VYPR
High severity7.8NVD Advisory· Published Mar 17, 2026· Updated Jun 17, 2026

CVE-2026-4295

CVE-2026-4295

Description

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory.

To remediate this issue, users should upgrade to version 0.8.0 or higher.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.