CVE-2026-11931 - Insecure Permissions on Authentication Token Cache File in Kiro IDE
Summary
Kiro IDE, an AI-powered development tool, had a security flaw in versions before 0.11.133 where authentication token cache files (files storing login credentials) were saved with world-readable permissions on macOS and Linux, meaning any user or process on the same computer could read them instead of just the owner.
Solution / Mitigation
Update Kiro IDE to version 0.11.133 or later.
Classification
Affected Vendors
Related Issues
GHSA-382c-vx95-w3p5: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-2589: The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-045-aws/
First tracked: June 15, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 85%