Amazon Kiro IDE Prompt Injection Flaw Exfiltrates Data

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Amazon's Kiro IDE (version 0.7.45 on Windows) contains a prompt injection flaw disclosed by Mindgard that lets attacker-controlled repository content transmit sensitive local data to an external endpoint via Kiro Powers — exploitation difficulty was rated 'low' and no CVE identifier was assigned.
- The exploit chain requires only two user actions: opening a malicious workspace file through 'File → Open Workspace From File' (rather than the folder directly) and then sending any message to the agent — no malicious prompt or reference to attacker content is needed.
- Amazon patched the flaw in Kiro IDE version 0.8.140 on January 15 after responsible disclosure, telling The Hacker News that customers should install the latest version to receive security updates.
- The disclosure extends a prior Mindgard finding in which steering-file directives caused Kiro to read local files and embed their contents into Markdown image requests transmitted to an external server.
- In June 2026, Amazon separately addressed CVE-2026-10591 (CVSS 8.8), an insufficient access control flaw that let a remote unauthenticated actor execute arbitrary commands through crafted writes to execution-sensitive paths like '.vscode/tasks.json' or '~/.kiro/settings/mcp.json'.
- Mindgard argues the findings expose a systemic problem: AI vulnerabilities emerge from interactions between model interpretation, application logic, tools, configuration, and external resources — a class of bugs traditional disclosure programs weren't designed to evaluate.
Why it matters: The Kiro disclosure lands alongside a cascade of similar flaws in Cursor, Claude Code, Gemini CLI, and Codex CLI, illustrating how agentic IDEs that merge repository content interpretation with tool execution create trust boundary failures. Amazon patched in version 0.8.140 on January 15, but the two-step user interaction (open workspace, send message) keeps the exploitation bar low.
Ask SkimNews



