Kiro IDE Vulnerability Allows Remote Code Execution
Kiro IDE versions before 0.11 have a critical flaw (CVE-2026-10591) that lets attackers execute arbitrary commands by writing to sensitive paths like .vscode/tasks.json. The vulnerability requires no authentication and triggers auto-execution when you open a folder. Update to version 0.11 or later immediately—this one needs your attention.
source: [aws/security-bulletin]