CVE-2026-18656
Received Received - Intake

Uncontrolled Search Path Element in Kiro IDE

Vulnerability report for CVE-2026-18656, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: AMZN

Description

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-05
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiro ide to 1.0.228 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows. It allows a remote unauthenticated attacker to execute arbitrary code by tricking a local user into opening a maliciously crafted project directory containing an executable. The attacker bypasses workspace trust protections to achieve this.

Detection Guidance

This vulnerability involves an uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows. To detect it, check the installed version of Kiro IDE by running 'kiro --version' or inspecting the application properties. If the version is below 1.0.228, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow an attacker to run malicious code on your system without authentication. This could lead to data theft, system compromise, or further network infiltration if the attacker gains control of your local user session.

Compliance Impact

This vulnerability could potentially allow unauthorized code execution on a user's system, which may lead to data breaches or unauthorized access to sensitive information. This could impact compliance with regulations like GDPR or HIPAA by compromising data confidentiality and integrity.

Mitigation Strategies

Upgrade Kiro IDE to version 1.0.228 or higher to address the uncontrolled search path element vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18656. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart