Kiro IDE Vulnerability: Arbitrary Code Execution Risk
Kiro IDE versions below 0.8.0 have a nasty security flaw (CVE-2026-4295) that lets attackers execute arbitrary code when you open a malicious project file. The vulnerability stems from weak trust boundary enforcement—basically, the IDE trusts project files too much. If you're using Kiro, update immediately to patch this critical issue.
source: [aws/security-bulletin]