AWS Latest Bulletins
Follow
CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
This bulletin addresses a security vulnerability in Kiro IDE, specifically CVE-2026-89332. Kiro IDE is an AI-powered development environment designed to assist developers. The vulnerability allows a malicious agent within an untrusted workspace to modify a project's settings file. This modification can redirect Kiro's Powers registry URL to an external server. Consequently, sensitive workspace data could be exfiltrated to this malicious endpoint. While Kiro presents the edit for user approval, the file modification occurs before the user response. Opening the Powers panel prior to approval triggers the data transmission. This issue affects Kiro IDE versions prior to 0.8.135. Users are advised to update to a secure version of Kiro IDE. Further details are available in the referenced article.