Showing 1 vulnerability on this page for Kiro IDE

Signals CISA KEV Ransomware Nuclei
Amazon vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.

CWE-427Aug 4, 2026
CVSS8.5v4.0EPSS0.159%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX