CVE-2026-4295
CVSS 7.8 HIGH: improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote… EPSS 0.2% (9º percentile).
Vulnerabilità ed exploit
Bedrock AgentCore Starter Toolkit (pre‑v0.1.13) ha omesso la verifica di proprietà S3 durante il build. Questa omissione può permettere a un attore remoto di iniettare codice e causare esecuzione nell'AgentCore Runtime per build successivi al 24/09/2025 (CVE-2026-4269). AWS API MCP Server (>=0.2.14, <1.3.9) presenta un path bypass nelle modalità no-access e workdir che può esporre file locali arbitrari al client MCP (CVE-2026-4270).
1 fonte · 17 mar
CVSS 7.8 HIGH: improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote… EPSS 0.2% (9º percentile).
AWS Security Bulletins
Arbitrary code execution via crafted project files in Kiro IDE
We identified CVE-2026-4295, where improper trust boundary enforcement allowed arbitrary code execution when a user opened a maliciously crafted project directory.</p> <p><b>Impacted versions:</b> < 0.8.0</p> <p><b>Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.</b></p>
originaleAWS Security Bulletins
CVE-2026-4269 - Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
<p><b>Bulletin ID:</b> 2026-008-AWS<br/> <b>Scope:</b> AWS<br/> <b>Content Type:</b> Important (requires attention)<br/> <b>Publication Date:</b> 2026/03/16 11:15 AM PDT</p> <p><b>Description:</b></p> <p>A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime.</p> <p><b>Impacted versions:</b> All versions of Bedrock AgentCore Starter Toolkit versions before v0.1.13.
originaleAWS Security Bulletins
CVE-2026-4270 - AWS API MCP File Access Restriction Bypass
By default, file operations are restricted to a designated working directory (workdir), but this can be configured to allow unrestricted file system access (unrestricted) or to block all local file path arguments entirely (no-access).</p> <p>We identified CVE-2026-4270: Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context.</p> <p><b>Impacted versions:</b> awslabs.aws-api-mcp-server >= 0.2.14, < 1.3.9</p> <p><b>Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.</b></p>
originalePart of the PlainSec briefing for 2026-03-18
Every edition of this story: Bug nei Tool AWS Permettono Esecuzione di Codice e Esposizione File