Kiro CLI Vulnerability Lets Attackers Run Commands Without Permission
Kiro CLI versions before 1.28.0 have a security issue (CVE-2026-9255) where missing input validation allows local attackers to execute arbitrary tools and shell commands without your approval by piping malicious content to stdin. This is important—update to version 1.28.0 or later immediately if you're using Kiro CLI.
source: [aws/security-bulletin]