bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-18657

show all
Tuesday, August 4, 2026

Kiro IDE and CLI on Windows: Critical Executable Resolution Vulnerability

Kiro IDE (versions 1.0.0–1.0.212) and Kiro CLI (pre-2.10.0) on Windows have a nasty path traversal issue—CVE-2026-18656 and CVE-2026-18657. A malicious project directory can plant an executable that runs before your system PATH, letting attackers execute arbitrary code when you open the folder. **Action required**: Update immediately if you're on Windows.

> source: aws.amazon.com