bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-5429

show all
Thursday, August 20, 2026

Kiro IDE XSS Vulnerability Requires Immediate Update

Kiro IDE versions before 0.8.140 have a cross-site scripting (XSS) flaw (CVE-2026-5429) in the webview that lets attackers execute arbitrary code through malicious workspace color themes. You need to update immediately if you're running an older version—the exploit triggers when you open a compromised workspace and trust the prompt. This is marked Important severity, so don't sleep on it.

source: [aws/security-bulletin]