Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.5
CVE-2026-18657
- EPSS 0.16%
- Veröffentlicht 04.08.2026 20:16:50
- Zuletzt bearbeitet 18.08.2026 14:43:56
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust p...
8.4
CVE-2026-9255
- EPSS 0.12%
- Veröffentlicht 22.05.2026 16:38:10
- Zuletzt bearbeitet 23.07.2026 16:10:00
Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. ...
1