CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
Bulletin ID: 2026-037-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/02/2026 08:45 AM PDT Description: Kiro is an agentic IDE users install on their desktop. We identified CVE-2026-10591. Insufficient access control restrictions in the file write tool in Kiro IDE prior to version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. Impacted versions: <0.11 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Insufficient file write restrictions may allow remote unauthenticated actors to execute arbitrary commands.
- Who is affected
- Users of Kiro IDE versions prior to 0.11.
- Urgency
- Remediation is important due to the risk of arbitrary command execution.
- Action
- Upgrade to Kiro IDE version 0.11 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Kiro IDE
Get an email when a new Kiro IDE advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-037-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-105910.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10591 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - Kiro IDE
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-75057: In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the ID…nvd · 2026-08-17
- unknownCVE-2026-73218: Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS al…nvd · 2026-08-11
- unknownCVE-2026-73217: Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS al…nvd · 2026-08-11
- highCVE-2026-9077: IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass …nvd · 2026-08-05
- mediumCVE-2026-64810: In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, a…nvd · 2026-07-23
- criticalCVE-2026-26718: A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application …nvd · 2026-07-15
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownOngoing updates on Copy.fail and variants2026-08-20