---
id: CVE-2026-95985
title: >-
  The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow
  remote unauthenticated actors to inject crafted instructions into the agent's
  context
summary: >-
  The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow
  remote unauthenticated actors to inject crafted instructions into the agent's
  context. When a user runs the agent in a crafted repository as an untrusted
  workspac…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-349
  - CWE-829
vendor: Amazon
product: Kiro IDE
affected:
  - kiro_ide < 1.0.242
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T19:36:39.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95985'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-117-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://kiro.dev/changelog/ide/1-0-242/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T17:23:54.377945Z'
ingestedAt: '2026-09-24T17:48:30.406Z'
---

## Overview

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.



We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
