AWS Kiro IDE Flaw Lets Hidden Web Prompts Execute Code on Developer Machines
ID: 9b5ebb3b-b27a-5749-bff6-d089f43ffad0
STIX ID: report--9b5ebb3b-b27a-5749-bff6-d089f43ffad0
Feed Name: Cyber Press
A security researcher discovered a critical prompt-injection vulnerability in AWS's agentic IDE Kiro that let attackers embed invisible instructions in ordinary web pages; when Kiro fetched and summarized those pages, it could silently register a malicious MCP server in ~/.kiro/settings/mcp.json and immediately execute attacker-controlled Node.js code without presenting a real approval prompt. The flaw affected specific Kiro versions (noted for macOS and Ubuntu), was reported and patched by AWS across releases (with verification by the researcher), and highlights a systemic risk in agentic coding tools where models cannot reliably separate data from executable instructions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
