CVE-2026-18657 Details
Description
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory. To remediate this issue, users should upgrade to version 2.10.0 or higher.
A vulnerability exists in Kiro CLI for Windows, prior to version 2.10.0, due to an uncontrolled search path element. This flaw may enable a remote, unauthenticated actor to execute arbitrary code by placing an executable in a maliciously crafted project directory. When a local user launches Kiro CLI from that directory, the executable can bypass workspace trust protections, potentially leading to unauthorized code execution.
Users are advised to upgrade to Kiro CLI version 2.10.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-074-aws/ | AMZN | Vendor Advisory |
| https://kiro.dev/changelog/cli/2-10/ | AMZN | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon kiro cli | < 2.10.0 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | AMZN |