Beveiligingsadvies

CVE-2026-10591

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-02 15:34:40
Laatst bijgewerkt 2026-06-03 03:56:03
Toegewezen door AMZN
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.