{"id":"CVE-2026-18656","published":"2026-08-04T20:16:50.410","lastModified":"2026-08-06T15:46:36.880","description":"An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.\n\n\n\nTo remediate this issue, users should upgrade to version 1.0.228 or higher.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-427"],"vendors":[],"products":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-074-aws/","tags":[]},{"url":"https://kiro.dev/changelog/ide/1-0/#patch-1-0-228","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a remote unauthenticated actor to execute arbitrary code by manipulating the project directory path in Kiro IDE versions before 1.0.228 on Windows.","exploitability":"Exploitation requires control over a maliciously crafted project directory and interaction from a local user opening it, making it moderately exploitable.","blast_radius":"If exploited, this could lead to full system compromise as the code execution bypasses workspace trust protections.","remediation":"Upgrade Kiro IDE to version 1.0.228 or higher immediately.","tags":["rce","auth-bypass","windows","ide"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:51:48.961Z"}}