Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory.
To remediate this issue, users should upgrade to version 0.8.0 or higher.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 0.8.0 or higher. | |
| Title | Arbitrary code execution via crafted project files in Kiro IDE | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-03-17T19:11:58.702Z
Reserved: 2026-03-16T17:38:37.520Z
Link: CVE-2026-4295
No data.
Status : Received
Published: 2026-03-17T20:16:14.840
Modified: 2026-03-17T20:16:14.840
Link: CVE-2026-4295
No data.
OpenCVE Enrichment
No data.