CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
Summary
Kiro IDE, a desktop application that uses agentic AI (an AI system that can take actions like writing files), has a vulnerability (CVE-2026-95985) in versions before 1.0.242 where an attacker can trick the AI into modifying important global configuration files when a user opens an untrusted workspace (a folder containing malicious code). This could let attackers run arbitrary commands (any code they want) on the user's computer.
Solution / Mitigation
Update Kiro IDE to version 1.0.242 or later.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-117-aws/
First tracked: September 24, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%