bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

Kiro IDE Command Injection Vulnerability (CVE-2026-0830)

Kiro IDE versions before 0.6.18 are vulnerable to command injection when opening maliciously crafted workspaces with specially named folders. This could let attackers execute arbitrary commands on your system. If you're using Kiro IDE, update to version 0.6.18 or later immediately—this one's worth your attention.

source: [aws/security-bulletin]