CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI

Cli ยท 2026-06-05

Actions

Rate this issue

Technical Details

Affected Versions prior to 1.28.0
Regions all
CVE IDs CVE-2026-9255
Migration Required Yes
Cost Impact Neutral

What This Means

For DevOps Teams

Update Kiro CLI to version 1.28.0 and apply the --no-interactive flag when piping content from untrusted sources to prevent potential security breaches due to CVE-2026-9255.

For Platform Teams

Integrate the updated Kiro CLI version 1.28.0 into your development workflows to enhance security and maintain compliance with the latest AWS security standards.

For Executives

Implement the latest Kiro CLI version 1.28.0 to mitigate the security risk of unauthorized tool execution and ensure secure AI-assisted coding practices within your organization.

Source

View original AWS announcement โ†’

Related Cli Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.