Impact
An uncontrolled search‑path element in Amazon Kiro CLI before version 2.10.0 on Windows allows an attacker who can place a malicious project directory that contains an executable to bypass workspace trust protections; when a local user launches Kiro CLI in that directory, the executable is resolved and executed with the user’s privileges. This flaw permits an unauthenticated actor to run arbitrary code on the target system, potentially compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Amazon Kiro CLI on Windows, versions earlier than 2.10.0.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and while an EPSS score is not available, the vulnerability is not currently listed in the CISA KEV catalog. Based on the CVE description, the likely attack vector requires the adversary to place a crafted project directory that contains a malicious executable on the local file system of a user who subsequently starts Kiro CLI. If this condition is met, the flaw can be exploited to execute code without authentication, giving an attacker control over the running user’s process context.
OpenCVE Enrichment