Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpcc-2ccj-gp68

Опубликовано: 17 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory.

To remediate this issue, users should upgrade to version 0.8.0 or higher.

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory.

To remediate this issue, users should upgrade to version 0.8.0 or higher.

EPSS

Процентиль: 4%
0.00016
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-829

Связанные уязвимости

CVSS3: 7.8
nvd
23 дня назад

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 0.8.0 or higher.

EPSS

Процентиль: 4%
0.00016
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-829