What happened
In a crafted repository opened as an untrusted workspace, an ordinary user message can cause the Kiro agent to write attacker-directed changes into auto-loaded global configuration paths.
2026-09-24
HighVendor postAnalysis of CVE-2026-95985, an Amazon Kiro flaw that let crafted repositories drive agent writes to auto-loaded global configuration.
What happened
In a crafted repository opened as an untrusted workspace, an ordinary user message can cause the Kiro agent to write attacker-directed changes into auto-loaded global configuration paths.
Why it matters
Unauthorized global configuration changes and potential arbitrary command execution with the developer's local privileges; no real-world exploitation was reported in the advisory.
Missing authorization check
Independent authorization for agent-originated writes outside the repository, especially writes to global agent configuration and executable tool definitions.
Would PP block it?
The prompt injection can still enter the model context, but the resolved destination, content, and requesting agent can be evaluated outside Kiro. A write to the global configuration directory without matching authority would fail closed.
Incident analysis
2026-09-24
AWS publishes security bulletin 2026-117-AWS and assigns CVE-2026-95985.
2026-09-24
Kiro IDE 1.0.242 is identified as the fixed release.
Authorization boundary
This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
A Runtime Gate can require a separately authenticated receipt before a Kiro-originated write crosses from an untrusted workspace into global configuration.
Start small
This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.