Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.
History

Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon aws Kiro Ide
Vendors & Products Amazon
Amazon aws Kiro Ide

Fri, 09 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Jan 2026 21:30:00 +0000

Type Values Removed Values Added
Description Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to version 0.6.18. Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.

Fri, 09 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Description Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to version 0.6.18.
Title Command Injection in Kiro GitLab Merge Request Helper
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published: 2026-01-09T21:10:09.310Z

Updated: 2026-01-09T21:18:53.768Z

Reserved: 2026-01-09T20:29:46.407Z

Link: CVE-2026-0830

cve-icon Vulnrichment

Updated: 2026-01-09T21:18:49.421Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-09T21:16:14.127

Modified: 2026-01-13T14:03:46.203

Link: CVE-2026-0830

cve-icon Redhat

No data.