We recommend you to upgrade to kiro-cli version 1.28.0 or later.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon kiro Cli |
|
| CPEs | cpe:2.3:a:amazon:kiro_cli:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon kiro Cli |
Fri, 22 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later. | |
| Title | Tool Execution Without Authorization via Piped Stdin in Kiro CLI | |
| First Time appeared |
Aws
Aws kiro Cli |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:aws:kiro_cli:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws kiro Cli |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-05-23T03:55:58.873Z
Reserved: 2026-05-21T20:55:28.520Z
Link: CVE-2026-9255
Updated: 2026-05-22T17:22:36.899Z
Status : Analyzed
Published: 2026-05-22T17:16:49.767
Modified: 2026-06-17T11:04:58.133
Link: CVE-2026-9255
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:34:06Z