Skip to content
AWSAWS-2026-074

AWS: code execution

UnratedCVE-2026-18656 · Published Aug 4, 2026 · updated Sep 9, 2026

Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657 , an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory. Impacted versions: Kiro IDE for Windows between versions 1.0.0 through 1.0.212 Kiro CLI for Windows prior to v2.10.0 Resolution: This issue has been addressed in Kiro IDE version 1.0.228 and in Kiro CLI version 2.10.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: No workaround available. References: CVE-2026-18656 CVE-2026-18657 Acknowledgements: We would like to thank Edo Maland for Kiro IDE issue through the coordinated vulnerability disclosure process. We would like to thank Emanuele Barbeno, Cyrill Bannwart, Urs Mueller, Lukasz D, Yves Bieri of Compass Securi...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657 , an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory. Impacted versions: Kiro IDE for Windows between versions 1.0.0 through 1.0.212 Kiro CLI for Windows prior to v2.10.0 Resolution: This issue has been addressed in Kiro IDE version 1.0.228 and in Kiro CLI version 2.10.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: No workaround available. References: CVE-2026-18656 CVE-2026-18657 Acknowledgements: We would like to thank Edo Maland for Kiro IDE issue through the coordinated vulnerability disclosure process. We would like to thank Emanuele Barbeno, Cyrill Bannwart, Urs Mueller, Lukasz D, Yves Bieri of Compass Security for collaborating on Kiro CLI issue through the coordinated vulnerability disclosure process Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-074-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657 , an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory. Impacted versions: Kiro IDE for Windows between versions 1.0.0 through 1.0.212 Kiro CLI for Windows prior to v2.10.0 Resolution: This issue has been addressed in Kiro IDE version 1.0.228 and in Kiro CLI version 2.10.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: No workaround available. References: CVE-2026-18656 CVE-2026-18657 Acknowledgements: We would like to thank Edo Maland for Kiro IDE issue through the coordinated vulnerability disclosure process. We would like to thank Emanuele Barbeno, Cyrill Bannwart, Urs Mueller, Lukasz D, Yves Bieri of Compass Security for collaborating on Kiro CLI issue through the coordinated vulnerability disclosure process Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Ama

Severity from
no source yet
Also known as
CVE-2026-18657

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.