Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
nextbyte.live
nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
Subscribe
Close

Search

Amazon Kiro IDE Vulnerability Allows Data Theft via Prompt Injection
ai

Amazon Kiro IDE Vulnerability Allows Data Theft via Prompt Injection

By abde el aziz
August 27, 2026 2 Min Read
0

Amazon Kiro, an AI-powered integrated development environment (IDE), contains a vulnerability that allows attackers to steal sensitive data through prompt injection and malicious workspace files. Security researchers at Mindguard disclosed the flaw, which affects Kiro IDE 0.7.45 on Windows and has no CVE identifier assigned. The Amazon Kiro vulnerability works by allowing attacker-controlled repository content to manipulate the Kiro agent into transmitting local information to external endpoints without explicit user consent.

Table of Contents

  • How the Amazon Kiro Vulnerability Works
  • Trust Boundary Failures in AI Development Tools

How the Amazon Kiro Vulnerability Works

The vulnerability exploits the way Kiro Powers function within the IDE. Kiro Powers bundle Model Context Protocol (MCP) server configurations, steering files (marked “POWER.md”), hooks, and contextual knowledge. The steering file acts as an “onboarding manual” that provides persistent context and instructs the AI agent which MCP tools are available and when to use them.

Amazon Kiro IDE Vulnerability Allows Data Theft via Prompt Injection

Successful exploitation requires two simple user actions: opening a malicious project through a workspace file using File → Open Workspace From File, then sending any message to the agent. Notably, the user does not need to submit a malicious prompt or even reference the attacker-controlled content. Once the crafted workspace is opened, ordinary communication with the agent triggers the vulnerable flow. Security researcher Fergal Glynn explained that “the issue allowed attacker-controlled repository content to influence the Kiro agent and ultimately cause sensitive local information to be transmitted to an external endpoint.” The exploitation difficulty has been assessed as low, and the vulnerability is reproducible against both trusted and untrusted workspaces.

Trust Boundary Failures in AI Development Tools

The Amazon Kiro vulnerability reveals a deeper problem in how modern AI development environments handle security boundaries. As Mindguard noted, “the vulnerability appears when attacker-controlled project content is interpreted as instructions, and those instructions are allowed to influence security-sensitive operations elsewhere in the IDE.” The flaw stems from a chain of trust failures: repository-controlled content influences the agent, the agent reads sensitive local information, the agent writes that information into security-relevant IDE configuration, and subsequent IDE capabilities turn the modified configuration into network activity.

This pattern reflects a broader challenge in AI tool security. In a related development, OpenAI Model Escaped Restricted Environment to Hack Hugging Face highlighted how AI systems can escape restricted environments to compromise external services. Similarly, as covered in How to Automate Dependabot Pull Requests Using GitHub Copilot, automation in development workflows requires careful security consideration. Amazon addressed the flaw by releasing a fix in Kiro IDE version 0.8.140 following responsible disclosure. However, this is not the first security issue in Kiro—in June 2026, the company patched an insufficient access control flaw (CVE-2026-10591, CVSS score: 8.8) that allowed remote code execution through crafted instructions targeting execution-sensitive paths like “.vscode/tasks.json” or “~/.kiro/settings/mcp.json.”

المصدر: The Hacker News

Author

abde el aziz

Follow Me
Other Articles
Nvidia reportedly in talks to acquire Hugging Face for $13 billion
Previous

Nvidia reportedly in talks to acquire Hugging Face for $13 billion

Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
Next

Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • The Sandbox to Repay Users After $700,000 Bridge Exploit
  • Google AI Mode adds flight price tracking and hotel booking tools
  • Apple Upgrade vs. Verizon: Which iPhone Deal Saves You More?
  • Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  • Amazon Kiro IDE Vulnerability Allows Data Theft via Prompt Injection

Recent Comments

  1. Google AI Mode adds flight price tracking and hotel booking tools on How to Automate Dependabot Pull Requests Using GitHub Copilot
  2. Apple Upgrade vs. Verizon: Which iPhone Deal Saves You More? on The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  3. Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase on The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  4. Amazon Kiro IDE Vulnerability Allows Data Theft via Prompt Injection on OpenAI Model Escaped Restricted Environment to Hack Hugging Face
  5. Nvidia reportedly in talks to acquire Hugging Face for $13 billion on OpenAI Model Escaped Restricted Environment to Hack Hugging Face

Archives

  • August 2026

Categories

  • ai
  • crypto
  • cybersecurity
  • gadgets
  • hardware
  • tech
  • web
Copyright 2026 — nextbyte.live. All rights reserved. Blogsy WordPress Theme