Every CVE whose affected-product data names Amazon Kiro Cli, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (2)
CVE-2026-18657 — CVSS 7.8 (high): An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute…
CVE-2026-9255 — CVSS 7.8 (high): Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary…