logo

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

ID: 9c78e159-21ef-50f1-bc8a-3aa69182464d

STIX ID: report--9c78e159-21ef-50f1-bc8a-3aa69182464d

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-27

Date Updated: 2026-08-28

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed a low-difficulty vulnerability in Amazon Kiro IDE (affecting version 0.7.45) that allows attacker-controlled repository content and steering files to influence the agent, read sensitive local data, and exfiltrate it to external endpoints when a crafted workspace file is opened and any message is sent; Amazon issued a fix in later Kiro releases. The report places this finding in the broader context of multiple high-severity flaws across AI development tools (including sandbox escapes, configuration tampering, and remote code execution) that create trust-boundary failures between model interpretation, application logic, and tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.