HOLY FUCK, that's amazing!
AWS's "agentic development environment" allowed remote code execution via the NAME OF A COLOUR THEME ππ€‘
https://aws.amazon.com/security/security-bulletins/rss/2026-012-aws/
CVE-2026-5429 - Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme
<p><b>Bulletin ID:</b> 2026-012-AWS<br/> <b>Scope:</b> AWS<br/> <b>Content Type:</b> Important (requires attention)<br/> <b>Publication Date:</b> 2026/04/02 11:30 AM PDT</p> <p><b>Description:</b></p> <p>Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents.</p> <p>We identified CVE-2026-5429, where unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a maliciously crafted color theme name when a local user opens the workspace. This issue requires the user to trust the workspace when prompted.</p> <p><b>Impacted versions:</b> < 0.8.140</p> <p><b>Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.</b></p>







βπ€ποΈπ§ | π«π π¦Ήπ¦π¦Ήπ π«