CVE-2026-18657
Received Received - Intake

Uncontrolled Search Path Element in Kiro CLI

Vulnerability report for CVE-2026-18657, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: AMZN

Description

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory. To remediate this issue, users should upgrade to version 2.10.0 or higher.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-05
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
kiro cli to 2.10.0 (exc)
kiro ide From 1.0.0 (inc) to 1.0.212 (inc)
kiro kiro_cli to 2.10.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-18657 is an uncontrolled search path element vulnerability in Kiro CLI for Windows before version 2.10.0. It allows a remote unauthenticated attacker to execute arbitrary code by placing a malicious executable in a project directory. When a local user opens the directory, the system may execute the malicious file instead of the intended Kiro CLI due to improper path resolution.

Detection Guidance

Detect this vulnerability by checking the installed version of Kiro CLI on Windows systems. Compare it against version 2.10.0 or higher. Commands to check the version may include 'kiro --version' or inspecting the installation directory for version files.

Impact Analysis

If you use Kiro CLI on Windows before version 2.10.0, an attacker could trick you into running malicious code by crafting a project directory with a file that executes instead of Kiro CLI. This could lead to unauthorized system access, data theft, or further compromise of your system.

Compliance Impact

This vulnerability could lead to unauthorized code execution on a user's system, potentially compromising sensitive data. For GDPR, this may result in unauthorized access to personal data, violating confidentiality requirements. For HIPAA, it could allow unauthorized access to protected health information, breaching security rules.

Mitigation Strategies

Upgrade Kiro CLI to version 2.10.0 or higher immediately. No workaround is available, so updating is the only mitigation. Verify the upgrade by checking the version again after installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18657. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart