Uncontrolled Search Path Vulnerability in Kiro CLI by Kiro
CVE-2026-18657
8.5HIGH
What is CVE-2026-18657?
An uncontrolled search path element vulnerability in Kiro CLI prior to version 2.10.0 on Windows allows remote unauthenticated attackers to execute arbitrary code. This is facilitated through a maliciously crafted project directory containing an executable, which can bypass workspace trust protections when a local user starts Kiro CLI within that directory. Users are strongly advised to upgrade to version 2.10.0 or higher to mitigate this risk.
Affected Version(s)
Kiro CLI 0 < 2.10.0
