CVE-2026-5429
Last modified
CVE-2026-5429 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should upgrade to version 0.8.140.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should upgrade to version 0.8.140.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AWS | Kiro IDE | >= 0.1, < 0.8.140 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-5429?
How severe is CVE-2026-5429?
How do I fix CVE-2026-5429?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54284sqlparse is a non-validating SQL parser module for Python. P…8.7
- CVE-2026-54285opentelemetry-js is the OpenTelemetry JavaScript Client. Pri…5.3
- CVE-2026-54286Hono is a Web application framework that provides support fo…5.9
- CVE-2026-54287Hono is a Web application framework that provides support fo…5.3
- CVE-2026-54288Hono is a Web application framework that provides support fo…6.5
- CVE-2026-54289Hono is a Web application framework that provides support fo…4.8
- CVE-2026-54290Hono is a Web application framework that provides support fo…7.1
- CVE-2026-54291pgjdbc is an open source postgresql JDBC Driver. In releases…5.9
- CVE-2026-54292Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-54293NLTK (Natural Language Toolkit) is a suite of open source Py…7.5
- CVE-2026-54294Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-54295Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
Are you affected by CVE-2026-5429?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
