logo

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

ID: 399be573-79bb-5ab5-9722-90d58a8e6877

STIX ID: report--399be573-79bb-5ab5-9722-90d58a8e6877

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: [email protected] (The Hacker News)

...
...

Kiro's agentic coding IDE could be tricked by hidden or injected web content to write a malicious Model Context Protocol (MCP) server entry into ~/.kiro/settings/mcp.json, reload it, and execute arbitrary commands as the developer. Intezer's proof-of-concept showed RCE via one-pixel white text on a documentation page; AWS later mitigated the class of bug by protecting sensitive paths and moving checks into the platform (fix confirmed in v0.11.130 and enforced in 1.0.x releases), though no CVE or confirmed in-the-wild exploitation was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.