CVE-2026-18657: Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory.
To remediate this issue, users should upgrade to version 2.10.0 or higher.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiro CLIto a version that resolves this vulnerability.Fixed in 2.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18657?
CVE-2026-18657 has a high severity rating of 8.5.
How do I fix CVE-2026-18657?
To mitigate CVE-2026-18657, update Kiro CLI to version 2.10.0 or later.
What does CVE-2026-18657 exploit?
CVE-2026-18657 exploits an uncontrolled search path element in Kiro CLI that may allow arbitrary code execution.
Who is affected by CVE-2026-18657?
Users of Kiro CLI on Windows prior to version 2.10.0 are affected by CVE-2026-18657.
Can CVE-2026-18657 lead to remote code execution?
Yes, CVE-2026-18657 allows a remote unauthenticated actor to execute arbitrary code.