Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cv6r-hx5v-c4m6

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.4
CVSS3: 7.8

Описание

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin.

We recommend you to upgrade to kiro-cli version 1.28.0 or later.

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin.

We recommend you to upgrade to kiro-cli version 1.28.0 or later.

EPSS

Процентиль: 2%
0.00119
Низкий

8.4 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.8
nvd
2 месяца назад

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later.

EPSS

Процентиль: 2%
0.00119
Низкий

8.4 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-862