CVE-2026-5429 is a high-severity vulnerability (CVSS 7.8) affecting Kiro IDE versions prior to 0.8.140, specifically due to unsanitized input in the Kiro Agent webview. This flaw allows a remote unauthenticated attacker to execute arbitrary code by crafting a malicious color theme name, which is triggered when a local user opens a workspace and trusts it. The attack vector is local and requires user interaction, but the potential impact on confidentiality, integrity, and availability is high. There is currently no evidence of active exploitation, and public exploit code is not available, with community discussion being minimal. Users should upgrade to Kiro IDE version 0.8.140 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1, < 0.8.140CPE match | cpe:2.3:a:amazon:kiro_ide:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.