Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhmj-6g9r-9vvq

Опубликовано: 04 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.

To remediate this issue, users should upgrade to version 1.0.228 or higher.

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.

To remediate this issue, users should upgrade to version 1.0.228 or higher.

EPSS

Процентиль: 6%
0.00163
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
nvd
около 1 месяца назад

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.

EPSS

Процентиль: 6%
0.00163
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-427