CVE-2026-18656 Details
Description
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.
A vulnerability exists in Kiro IDE for Windows versions 1.0.0 prior to 1.0.228 and Kiro CLI for Windows prior to version 2.10.0. The issue stems from an uncontrolled search path element that may enable a remote, unauthenticated actor to execute arbitrary code. This is achieved by crafting a malicious project directory that contains an executable, which can bypass workspace trust protections when the local user accesses the directory.
Users are advised to upgrade to Kiro IDE version 1.0.228 or Kiro CLI version 2.10.0. For Kiro IDE, the latest version can be downloaded from the Kiro website. Kiro CLI users should also download the latest version from the Kiro website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-074-aws/ | AMZN | Vendor Advisory |
| https://kiro.dev/changelog/ide/1-0/#patch-1-0-228 | AMZN | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon kiro ide | < 1.0.228 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | AMZN |