CVE-2026-4295 describes an improper trust boundary enforcement vulnerability in Kiro IDE versions prior to 0.8.0, affecting all supported platforms. This flaw allows a remote unauthenticated attacker to execute arbitrary code when a local user opens a maliciously crafted project directory. Rated High with a CVSS score of 7.8, exploitation requires user interaction but has low attack complexity and no prior privileges, leading to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no public exploit code available, the vulnerability has garnered some community discussion and media coverage. Users are advised to upgrade to version 0.8.0 or higher to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 0.8.0CPE match | cpe:2.3:a:amazon:kiro_ide:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.