CVE-2026-9255

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later.
Configurations

Configuration 1 (hide)

cpe:2.3:a:amazon:kiro_cli:*:*:*:*:*:*:*:*

History

04 Jun 2026, 15:21

Type Values Removed Values Added
First Time Amazon kiro Cli
Amazon
CPE cpe:2.3:a:amazon:kiro_cli:*:*:*:*:*:*:*:*
References () https://aws.amazon.com/security/security-bulletins/2026-035-aws/ - () https://aws.amazon.com/security/security-bulletins/2026-035-aws/ - Vendor Advisory
References () https://kiro.dev/changelog/cli/1-28/ - () https://kiro.dev/changelog/cli/1-28/ - Release Notes

22 May 2026, 18:28

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-22 17:16

Updated : 2026-06-04 15:21


NVD link : CVE-2026-9255

Mitre link : CVE-2026-9255

CVE.ORG link : CVE-2026-9255


JSON object : View

Products Affected

amazon

  • kiro_cli
CWE
CWE-862

Missing Authorization