← Back to search

CVE-2026-18656

7.8 HIGH

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows a remote unauthenticated actor to execute arbitrary code by manipulating the project directory path in Kiro IDE versions before 1.0.228 on Windows.
Exploitability
Exploitation requires control over a maliciously crafted project directory and interaction from a local user opening it, making it moderately exploitable.
Blast radius
If exploited, this could lead to full system compromise as the code execution bypasses workspace trust protections.
Prioritized remediation
Upgrade Kiro IDE to version 1.0.228 or higher immediately.
rceauth-bypasswindowside

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-427

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.