← Back to search

CVE-2026-18657

7.8 HIGH

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows a remote unauthenticated actor to execute arbitrary code by manipulating the search path in Kiro CLI versions before 2.10.0 on Windows.
Exploitability
Exploitation requires control over a project directory and starting Kiro CLI within it; moderately hard due to workspace trust protections but can be bypassed with a maliciously crafted directory.
Blast radius
If exploited, the impact is high as it could lead to full code execution on affected systems, potentially leading to data loss or system compromise.
Prioritized remediation
Upgrade Kiro CLI to version 2.10.0 or higher immediately.
rcecode-executionwindowscli

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory. To remediate this issue, users should upgrade to version 2.10.0 or higher.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-427

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.