Kiro IDE Command Injection Vulnerability in GitLab Merge Request Helper

Vulnerability

A command injection vulnerability has been identified in the Kiro GitLab Merge-Request helper, present in Kiro IDE versions prior to 0.6.18. The issue arises when the application processes workspace folder names that have been specially crafted to include injected commands, allowing for arbitrary command execution.

Impact

Exploitation of this vulnerability could lead to arbitrary command execution on the user's system.

Remediation

Users are advised to update Kiro IDE to version 0.6.18 or later.

Added: Jan 9, 2026, 9:18 PM
Updated: Jan 9, 2026, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.4
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.