logo

A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool

ID: f22055a0-a823-54ef-ad1d-fba67a5292d9

STIX ID: report--f22055a0-a823-54ef-ad1d-fba67a5292d9

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Abinaya

...
...

A prompt-injection vulnerability in AWS Kiro (an AI-powered IDE) allows hidden text on webpages to instruct the agent to modify the Model Context Protocol configuration (~/.kiro/settings/mcp.json). Because Kiro auto-reloads and executes commands from that file and the file is unprotected, attackers can achieve silent remote code execution on a developer's machine — a proof-of-concept demonstrated deploying a Node.js payload that exfiltrates system information. AWS issued fixes in version 0.11.130; the report warns that relying on user approval as a security boundary in AI agents is insufficient and calls for stronger system-level protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.