PT-2026-67827 · Kiro Cli · Kiro Cli

·

CVE-2026-18657

·

Published

2026-08-04

·

Updated

2026-08-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiro CLI versions prior to 2.10.0
Description On Windows, an uncontrolled search path element allows a remote unauthenticated actor to execute arbitrary code. This occurs when a local user starts the application in a maliciously crafted project directory containing an executable, which bypasses workspace trust protections.
Recommendations Upgrade to version 2.10.0 or higher.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18657

Affected Products

Kiro Cli