What is CVE-2026-18657?
This vulnerability exists in Kiro CLI versions prior to 2.10.0 on Windows. A remote unauthenticated actor may execute arbitrary code by bypassing workspace trust protections through a malicious project directory containing an executable, triggered when a local user starts Kiro CLI. Users should immediately upgrade to version 2.10.0 or later.
Azərbaycanca: Bu boşluq Windows üzərində Kiro CLI-nin 2.10.0-dan əvvəlki versiyalarında aşkarlanıb. Uzaqdan autentifikasiya olunmamış şəxs, zərərli layihə qovluğundakı işə salınan fayl vasitəsilə iş sahəsi etibarını keçərək ixtiyari kod icra edə bilər. İstifadəçilər dərhal 2.10.0 və ya daha yeni versiyaya yeniləməlidirlər.
FAQ2
Which versions of Kiro CLI are affected by the vulnerability that may allow arbitrary code execution?
This vulnerability affects all versions of Kiro CLI prior to 2.10.0 on Windows.
How is CVE-2026-18657 exploited?
A remote unauthenticated actor may execute code by bypassing workspace trust protections through an executable inside a malicious project directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.