CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
Summary
Kiro IDE (an AI-assisted development environment) had a vulnerability where an AI agent could modify workspace settings files in untrusted repositories, potentially redirecting the Powers panel (a UI component for extensions) to send sensitive workspace data to external servers. Although users were shown a prompt asking for approval, the malicious settings were already written to disk, so opening the Powers panel before responding would trigger the data leak.
Classification
Affected Vendors
Related Issues
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-111-aws/
First tracked: September 11, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 85%