High severity7.8NVD Advisory· Published Apr 2, 2026· Updated Apr 3, 2026
CVE-2026-5429
CVE-2026-5429
Description
Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace when prompted.
To remediate this issue, users should upgrade to version 0.8.140.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.