PT-2026-67827 · Kiro Cli · Kiro Cli
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kiro CLI versions prior to 2.10.0
Description
On Windows, an uncontrolled search path element allows a remote unauthenticated actor to execute arbitrary code. This occurs when a local user starts the application in a maliciously crafted project directory containing an executable, which bypasses workspace trust protections.
Recommendations
Upgrade to version 2.10.0 or higher.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiro Cli