HarborGuard / CVE
Back to search
HIGHCVE-2026-0830Published Modified CNA AMZN

CVE-2026-0830: Command Injection in Kiro GitLab Merge Request Helper

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.

Metrics

CVSS v4.0
8.4
Severity
HIGH
Fixed in
0.6.18
Affected Products
1

Fix available

0.6.18
Patch commits
Affected packages
  • AWS / Kiro IDE
    < 0.6.18 (from 0)
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N