Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces.
To mitigate, users should update to the latest version.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-09 21:16
Updated : 2026-01-13 14:03
NVD link : CVE-2026-0830
Mitre link : CVE-2026-0830
CVE.ORG link : CVE-2026-0830
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
