CVE-2026-18656
7.8 HIGHPublished 2026-08-04 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw allows a remote unauthenticated actor to execute arbitrary code by manipulating the project directory path in Kiro IDE versions before 1.0.228 on Windows.
- Exploitability
- Exploitation requires control over a maliciously crafted project directory and interaction from a local user opening it, making it moderately exploitable.
- Blast radius
- If exploited, this could lead to full system compromise as the code execution bypasses workspace trust protections.
- Prioritized remediation
- Upgrade Kiro IDE to version 1.0.228 or higher immediately.
rceauth-bypasswindowside
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-427
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.