bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

Kiro CLI Vulnerability Lets Attackers Run Commands Without Permission

Kiro CLI versions before 1.28.0 have a security issue (CVE-2026-9255) where missing input validation allows local attackers to execute arbitrary tools and shell commands without your approval by piping malicious content to stdin. This is important—update to version 1.28.0 or later immediately if you're using Kiro CLI.

source: [aws/security-bulletin]