PT-2026-67826 · Kiro Ide · Kiro Ide

CVE-2026-18656

·

Published

2026-08-04

·

Updated

2026-08-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiro IDE versions prior to 1.0.228
Description An uncontrolled search path element on Windows allows a remote unauthenticated actor to execute arbitrary code. This occurs when a local user opens a maliciously crafted project directory containing an executable, which bypasses workspace trust protections.
Recommendations Upgrade to version 1.0.228 or higher.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18656

Affected Products

Kiro Ide