VYPR

Kiro Ide

by AWS

CVEs (2)

  • CVE-2026-4295HigMar 17, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user…

  • CVE-2026-11931MedJun 15, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600). To remediate this…