CVE-2026-10591
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Jun 02, 2026
Vendor
unknown
Description
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.