CVE-2026-18656: An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted pro
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.
To remediate this issue, users should upgrade to version 1.0.228 or higher.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18656
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-186560.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18656 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for An uncontrolled search
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-66344: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Sea…nvd · 2026-08-05
- highCVE-2026-18657: An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a…nvd · 2026-08-04
- highCVE-2026-48388: Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability th…nvd · 2026-07-28
- highCVE-2026-8164: Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and …nvd · 2026-07-28
- highGHSA-7g7r-gx96-252g: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-build…ghsa · 2026-07-24
- mediumCVE-2026-63144: Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a speciall…nvd · 2026-07-21
More from NVD Recent CVEs
- highCVE-2026-8325: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds …2026-08-06
- highCVE-2026-7867: A flaw was found in udisks2. A local attacker with an active console session can exploit insuff…2026-08-06
- highCVE-2026-7406: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untr…2026-08-06
- mediumCVE-2026-7405: A maliciously crafted TIF file, when parsed through certain Autodesk products during image impo…2026-08-06
- mediumCVE-2026-71555: PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.…2026-08-06