CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows

unknownCVE-2026-18656CVE-2026-18657
Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657, an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory. Impacted versions: - Kiro IDE for Windows between versions 1.0.0 through 1.0.212 - Kiro CLI for Windows prior to v2.10.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CSIRTS triage

vendor: AWSproduct: Kiro IDE, Kiro CLIRemote code executionCode injectionaffected: Kiro IDE for Windows 1.0.0 through 1.0.212; Kiro CLI for Windows prior to v2.10.0
What
Uncontrolled search path element on Windows allows arbitrary code execution via malicious executable in project directory.
Who is affected
Windows users of Kiro IDE (1.0.0-1.0.212) and Kiro CLI (prior to 2.10.0) opening untrusted project directories.
Urgency
Critical; local arbitrary code execution via directory traversal is exploitable if user opens malicious project.
Action
Update Kiro IDE to version after 1.0.212 and Kiro CLI to v2.10.0 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Kiro IDE, Kiro CLI

Get an email when a new Kiro IDE, Kiro CLI advisory drops — max one per day, one-click unsubscribe.

Details

Source
AWS Security Bulletins (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-074-aws/

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-18656coverage & exploitation statusNVD · CVE.org
CVE-2026-18657coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for & CVE-2026-18657 -

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from AWS Security Bulletins