Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600). To remediate this issue, users should upgrade to Kiro IDE version 0.11.133 or later. After upgrading and restarting the application, the cache file permissions are automatically updated on the next token refresh. Users operating in a multi-user environment can invalidate existing tokens by reauthenticating.
History

Mon, 15 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Description Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600). To remediate this issue, users should upgrade to Kiro IDE version 0.11.133 or later. After upgrading and restarting the application, the cache file permissions are automatically updated on the next token refresh. Users operating in a multi-user environment can invalidate existing tokens by reauthenticating.
Title Insecure Permissions on Authentication Token Cache File in Kiro IDE
First Time appeared Aws
Aws kiro Ide
Weaknesses CWE-276
CPEs cpe:2.3:a:aws:kiro_ide:*:*:linux:*:*:*:*:*
cpe:2.3:a:aws:kiro_ide:*:*:macos:*:*:*:*:*
Vendors & Products Aws
Aws kiro Ide
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-06-15T20:08:12.566Z

Reserved: 2026-06-10T18:47:16.836Z

Link: CVE-2026-11931

cve-icon Vulnrichment

Updated: 2026-06-15T20:08:07.870Z

cve-icon NVD

Status : Received

Published: 2026-06-15T20:16:25.290

Modified: 2026-06-15T20:16:25.290

Link: CVE-2026-11931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.