Uncontrolled Search Path Element in Kiro IDE Affects Windows Users
CVE-2026-18656
8.5HIGH
What is CVE-2026-18656?
Kiro IDE prior to version 1.0.228 contains a vulnerability that may permit remote unauthenticated users to execute arbitrary code. This threat arises from an uncontrolled search path element which, when exploited via a specially crafted project directory, can circumvent the workspace trust protections. Users should promptly upgrade to version 1.0.228 or later to enhance their security posture.
Affected Version(s)
Kiro IDE 1.0.0 <= 1.0.212
