Vulnerability Description
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Kiro Ide | < 0.6.18 |
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-001-AWS/Vendor Advisory
- https://kiro.dev/changelog/spec-correctness-and-cli/Release Notes
FAQ
What is CVE-2026-0830?
CVE-2026-0830 is a vulnerability with a CVSS score of 7.8 (HIGH). Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously craft...
How severe is CVE-2026-0830?
CVE-2026-0830 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-0830?
Check the references section above for vendor advisories and patch information. Affected products include: Amazon Kiro Ide.