Kiro IDE Command Injection Vulnerability in GitLab Merge Request Helper
Vulnerability
A command injection vulnerability has been identified in the Kiro GitLab Merge-Request helper, present in Kiro IDE versions prior to 0.6.18. The issue arises when the application processes workspace folder names that have been specially crafted to include injected commands, allowing for arbitrary command execution.
Impact
Exploitation of this vulnerability could lead to arbitrary command execution on the user's system.
Remediation
Users are advised to update Kiro IDE to version 0.6.18 or later.
Added: Jan 9, 2026, 9:18 PM
Updated: Jan 9, 2026, 10:24 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
4.4remediation
7.7relevance
2.0threat
0.0urgency
2.9incentive
0.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
