Skip to main content

CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows

Bulletin ID: 2026-074-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/04/2026 12:30 PM PDT

Description:

Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657, an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory.

Impacted versions:

  • Kiro IDE for Windows between versions 1.0.0 through 1.0.212
  • Kiro CLI for Windows prior to v2.10.0

Resolution:

This issue has been addressed in Kiro IDE version 1.0.228 and in Kiro CLI version 2.10.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

No workaround available.

References:

Acknowledgements:

We would like to thank Edo Maland for Kiro IDE issue through the coordinated vulnerability disclosure process.

We would like to thank Emanuele Barbeno, Cyrill Bannwart, Urs Mueller, Lukasz D, Yves Bieri of Compass Security for collaborating on Kiro CLI issue through the coordinated vulnerability disclosure process


Please email aws-security@amazon.com with any security questions or concerns.