CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
Kiro Ide ยท 2026-09-11
Actions
Technical Details
| Affected Versions | < 0.8.135 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-89332 |
| Migration Required | Yes |
| Cost Impact | Neutral |
What This Means
For DevOps Teams
Update Kiro IDE to version 0.8.135 or greater to address CVE-2026-89332, a critical security vulnerability that could lead to sensitive workspace data exfiltration.
For Platform Teams
Deploy the updated Kiro IDE version 0.8.135 to ensure the security of development environments and protect sensitive project data from potential exfiltration attacks.
For Executives
Implement the latest Kiro IDE version 0.8.135 to mitigate the risk of sensitive data exfiltration and maintain regulatory compliance, safeguarding company reputation and customer trust.
Source
Related Kiro Ide Updates
- Amazon Bedrock Managed Knowledge Base adds APIs and console support for debugging document-level access control (2026-09-09)
- CVE-2026-11931 - Insecure Permissions on Authentication Token Cache File in Kiro IDE (2026-08-20)
- AWS Lambda console extends console-to-IDE integration to Kiro and Cursor (2026-08-06)