Kiro IDE XSS Vulnerability Requires Immediate Update
Kiro IDE versions before 0.8.140 have a cross-site scripting (XSS) flaw (CVE-2026-5429) in the webview that lets attackers execute arbitrary code through malicious workspace color themes. You need to update immediately if you're running an older version—the exploit triggers when you open a compromised workspace and trust the prompt. This is marked Important severity, so don't sleep on it.
source: [aws/security-bulletin]