Impact
An uncontrolled search path element in Kiro IDE version 1.0.228 and earlier on Windows can allow a remote, unauthenticated attacker to execute arbitrary code. The flaw is triggered when a local user opens a project directory that contains a malicious executable; the directory name can circumvent workspace trust protections, causing the IDE to load and run the executable. The vulnerability is a classic path manipulation weakness and is classified as CWE‑427.
Affected Systems
The affected product is Amazon's Kiro IDE on Windows operating systems, specifically any release before 1.0.228. Users running earlier versions of the IDE are susceptible, regardless of other software installed.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the lack of an EPSS score means the exploitation probability is unknown, but the vulnerability remains exploitable due to the remote input vector presented by untrusted project directories. The product is not listed in the CISA KEV catalog, but the potential for executable code execution by an unauthenticated actor makes it a critical issue. Attackers can trigger the flaw simply by creating a specially named project directory containing an executable and causing a user to open that directory.
OpenCVE Enrichment