Back to overview

CVE-2026-11931

MEDIUM
5.5
CVSS 3.1
Description
Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600). To remediate this issue, users should upgrade to Kiro IDE version 0.11.133 or later. After upgrading and restarting the application, the cache file permissions are automatically updated on the next token refresh. Users operating in a multi-user environment can invalidate existing tokens by reauthenticating.

Metadata

CVE ID
CVE-2026-11931
State
PUBLISHED
Assigner
AMZN
Reserved
2026-06-10 18:47 UTC
Published
2026-06-15 18:33 UTC
Last updated
2026-06-15 20:08 UTC
Primary CWE
CWE-276
CWE-276 Incorrect default permissions
Vendor / Product
AWS / Kiro IDE
Sources
cve.org  ·  NVD

Severity & Metrics

5.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
AWS Kiro IDE Linux,MacOS 0 < 0.11.133
Weakness (CWE)
CWESourceDescription
CWE-276 cna CWE-276 Incorrect default permissions
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.8 MEDIUM 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
5.5 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Back to overview