๐Ÿ” CVE Alert

CVE-2026-18657

HIGH 7.8

Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory. To remediate this issue, users should upgrade to version 2.10.0 or higher.

CWE CWE-427
Vendor amazon
Product kiro cli
Published Aug 4, 2026
Last Updated Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for amazon kiro cli

Be the first to know when new high vulnerabilities affecting amazon kiro cli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Amazon / Kiro CLI
0 < 2.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
kiro.dev: https://kiro.dev/changelog/cli/2-10/ aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-074-aws/

Credits

Compass Security