Boletines de Vulnerabilidades

CVE-2026-0830

   
Software afectado GITLAB
 
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces.

To mitigate, users should update to the latest version.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-0830