๐Ÿ” CVE Alert

CVE-2026-18656

HIGH 7.8

Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.

CWE CWE-427
Vendor amazon
Product kiro ide
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for amazon kiro ide

Be the first to know when new high vulnerabilities affecting amazon kiro ide are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Amazon / Kiro IDE
1.0.0 โ‰ค 1.0.212

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
kiro.dev: https://kiro.dev/changelog/ide/1-0/#patch-1-0-228 aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-074-aws/