Known Vulnerabilities for Kiro Cli by Amazon
Listed below are 2 of the newest known vulnerabilities associated with "Kiro Cli" by "Amazon".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89332 json | Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-56678 json | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key buil... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-18657 json | An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor t... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-18656 json | An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor ... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-11931 json | Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token ca... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-9255 json | Not Provided | 2026-05-22 | 2026-07-23 |