CVE-2026-18656 HIGH

CVE-2026-18656: Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows

Vendor Amazon
Product Kiro IDE
Weakness CWE-427
Published August 4, 2026
Last update August 5, 2026

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.

Key dates

02Disclosure timeline

August 4, 2026 CVE published
August 5, 2026 Record updated