CVE-2026-11931 PUBLISHED

Insecure Permissions on Authentication Token Cache File in Kiro IDE

Assigner: AMZN
Reserved: 10.06.2026 Published: 15.06.2026 Updated: 15.06.2026

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600).

To remediate this issue, users should upgrade to Kiro IDE version 0.11.133 or later. After upgrading and restarting the application, the cache file permissions are automatically updated on the next token refresh. Users operating in a multi-user environment can invalidate existing tokens by reauthenticating.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor AWS
Product Kiro IDE
Versions Default: unaffected
  • affected from 0 to 0.11.133 (excl.)

Credits

  • BeyondTrust Phantom Labs finder

References

Problem Types

  • CWE-276 Incorrect default permissions CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs