Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
ID: 9c78e159-21ef-50f1-bc8a-3aa69182464d
STIX ID: report--9c78e159-21ef-50f1-bc8a-3aa69182464d
Feed Name: The Hacker News
Cybersecurity researchers disclosed a low-difficulty vulnerability in Amazon Kiro IDE (affecting version 0.7.45) that allows attacker-controlled repository content and steering files to influence the agent, read sensitive local data, and exfiltrate it to external endpoints when a crafted workspace file is opened and any message is sent; Amazon issued a fix in later Kiro releases. The report places this finding in the broader context of multiple high-severity flaws across AI development tools (including sandbox escapes, configuration tampering, and remote code execution) that create trust-boundary failures between model interpretation, application logic, and tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
