Описание
Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin.
We recommend you to upgrade to kiro-cli version 1.28.0 or later.
Ссылки
- Vendor Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 1.28.0 (исключая)
cpe:2.3:a:amazon:kiro_cli:*:*:*:*:*:*:*:*
EPSS
Процентиль: 2%
0.00119
Низкий
7.8 High
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 7.8
github
2 месяца назад
Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later.
EPSS
Процентиль: 2%
0.00119
Низкий
7.8 High
CVSS3
Дефекты
CWE-862