To mitigate, users should update to the latest version.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon kiro Ide
|
|
| CPEs | cpe:2.3:a:amazon:kiro_ide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon kiro Ide
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon aws Kiro Ide |
|
| Vendors & Products |
Amazon
Amazon aws Kiro Ide |
Fri, 09 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to version 0.6.18. | Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version. |
Fri, 09 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to version 0.6.18. | |
| Title | Command Injection in Kiro GitLab Merge Request Helper | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-01-09T21:18:53.768Z
Reserved: 2026-01-09T20:29:46.407Z
Link: CVE-2026-0830
Updated: 2026-01-09T21:18:49.421Z
Status : Analyzed
Published: 2026-01-09T21:16:14.127
Modified: 2026-04-28T17:41:17.557
Link: CVE-2026-0830
No data.
OpenCVE Enrichment
Updated: 2026-04-18T07:30:36Z