bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, September 24, 2026

Kiro IDE Security Alert: Update Required for CVE-2026-95985

Kiro IDE versions before 1.0.242 have a nasty vulnerability (CVE-2026-95985) that lets attackers inject malicious commands into your agent's context when working in untrusted workspaces. The file write tool can modify global config files without permission, potentially leading to arbitrary code execution. **Action required:** Update to version 1.0.242 or later immediately if you're using Kiro.

source: [aws/security-bulletin]