VMTech
Discuss a project

Amazon patches Kiro IDE prompt injection flaw enabling data exfiltration

Amazon patches Kiro IDE prompt injection flaw enabling data exfiltration

Amazon has fixed a prompt-injection vulnerability in its Kiro agentic integrated development environment that could allow attacker-controlled repository content to trigger the exfiltration of sensitive local workspace data. Mindguard reproduced the issue in Kiro IDE 0.7.45 on Windows; Amazon implemented a fix in version 0.8.140. The latest version cited in the report is 1.0.337.

The flaw has no CVE identifier. Researcher Fergal Glynn said malicious project content could influence the Kiro agent and ultimately transmit sensitive local information to an external endpoint. Mindguard assessed exploitation difficulty as low, although the attack requires two user actions.

Workspace opening path creates the trigger

A victim must open a malicious project through a workspace file using File → Open Workspace From File, rather than opening its folder directly, and then send a message to the agent. Mindguard said the issue is reproducible in both trusted and untrusted workspaces.

Once those conditions are met, the user does not need to submit an attacker-crafted prompt or explicitly mention repository content. Sending any message can activate the vulnerable flow, potentially causing workspace data to be sent externally without the user asking Kiro to access or transmit it.

Kiro Powers broaden the affected workflow

Kiro Powers package Model Context Protocol server configurations, POWER.md steering files, hooks and contextual knowledge. The steering file acts as persistent guidance for the agent, including which MCP tools are available and when they should be used.

Mindguard described the problem as a trust-boundary failure spanning multiple stages: repository-controlled content can influence the agent; the agent can read local information; it can write that information into security-relevant IDE configuration; and another capability can turn the altered configuration into network activity. The finding illustrates how interpretation, tool use, configuration and external connectivity can combine inside an AI development workflow.

A continuing class of AI development tool risk

The disclosure builds on an earlier Mindguard finding in which steering-file directives could cause local information to be inserted into a Markdown image request and sent to an external server. Amazon also addressed CVE-2026-10591 in June 2026, an insufficient access control issue with a CVSS score of 8.8 that could enable unauthenticated remote command execution through crafted instructions writing to execution-sensitive paths.

For engineering organizations, the practical implication is to keep Kiro updated, treat workspace files and repository instructions as potentially untrusted, and review agent permissions, MCP configuration changes and outbound network activity as a single execution path.

#cybersecurity#promptinjection#aidevtools#appsec
Open analytics
On the site 0 views
min read 3 27.08.2026
Instagram

Amazon patches Kiro IDE prompt injection flaw enabling data exfiltration

Open the post on Instagram ↗