Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin.
We recommend you to upgrade to kiro-cli version 1.28.0 or later.
References
| Link | Resource |
|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-035-aws/ | Vendor Advisory |
| https://kiro.dev/changelog/cli/1-28/ | Release Notes |
Configurations
History
No history.
Information
Published : 2026-05-22 17:16
Updated : 2026-07-23 16:10
NVD link : CVE-2026-9255
Mitre link : CVE-2026-9255
CVE.ORG link : CVE-2026-9255
JSON object : View
Products Affected
amazon
- kiro_cli
CWE
CWE-862
Missing Authorization
