Hidden text on a webpage was able to make AWS Kiro rewrite its config and launch an attacker’s code

Colleagues, I’d like to draw attention to a cybersecurity issue in AWS Kiro.
I came across an example in which hidden text on a regular web page managed to prompt an agentic IDE to rewrite mcp.json and run attacker-controlled code on a developer’s machine.
The issue was that approval was not a real barrier: Kiro automatically re-read the config and executed the server described there. AWS has already released a fix; no CVE has been issued for this case.
Why this matters: you cannot trust a model with changes to sensitive files without platform-level protection, not just confirmation prompts.
How do you assess the risks of such AI IDEs in the workflow?
#cybersecurity #AWS #PromptInjection #AIsecurity


Latest comments
No comments yet.