Ad

CVE-2026-5429

HIGH CVSS 4.0: 7.1 EPSS 0.03%
Updated Apr 03, 2026
Unsanitized
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions before 0.8.140
Fixed In 0.8.140
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Unsanitized
Public PoC No

Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should upgrade to version 0.8.140.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0