{"id":"CVE-2026-18657","published":"2026-08-04T20:16:50.570","lastModified":"2026-08-06T15:46:36.880","description":"An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory.\n\n\n\nTo remediate this issue, users should upgrade to version 2.10.0 or higher.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-427"],"vendors":[],"products":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-074-aws/","tags":[]},{"url":"https://kiro.dev/changelog/cli/2-10/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a remote unauthenticated actor to execute arbitrary code by manipulating the search path in Kiro CLI versions before 2.10.0 on Windows.","exploitability":"Exploitation requires control over a project directory and starting Kiro CLI within it; moderately hard due to workspace trust protections but can be bypassed with a maliciously crafted directory.","blast_radius":"If exploited, the impact is high as it could lead to full code execution on affected systems, potentially leading to data loss or system compromise.","remediation":"Upgrade Kiro CLI to version 2.10.0 or higher immediately.","tags":["rce","code-execution","windows","cli"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:51:55.426Z"}}