{"data":{"id":"13ac0bb6-aa65-4913-8af2-f6f3106d6a71","title":"CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces","summary":"Kiro IDE, a desktop application that uses agentic AI (an AI system that can take actions like writing files), has a vulnerability (CVE-2026-95985) in versions before 1.0.242 where an attacker can trick the AI into modifying important global configuration files when a user opens an untrusted workspace (a folder containing malicious code). This could let attackers run arbitrary commands (any code they want) on the user's computer.","solution":"Update Kiro IDE to version 1.0.242 or later.","labels":["security"],"sourceUrl":"https://aws.amazon.com/security/security-bulletins/rss/2026-117-aws/","publishedAt":"2026-09-24T17:21:34.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["prompt_injection","supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Kiro IDE"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-24T17:21:34.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}