Beveiligingsadvies

CVE-2026-0830

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-09 21:10:09
Laatst bijgewerkt 2026-01-09 21:18:53
Toegewezen door AMZN
CVSS-score 8.4
Status PUBLISHED

Beschrijving

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.