The record
Written from the 2 reports below. Nothing here is unsourced.
- Researchers at Intezer and Kodem Security found that Amazon's Kiro IDE could be tricked into running attacker code through hidden text on a web page, via a prompt injection that made the agent write a malicious entry into its own MCP configuration file without approval.
- The file reloads automatically and launches whatever commands it lists, so the code ran with the developer's privileges even when Kiro showed a warning pop-up.
- AWS has fixed the issue by making sensitive files like mcp. protected paths requiring explicit approval, with the fix confirmed in version 0.11.130.
- This is the third time the same class of bug has been found in Kiro since its 2025 launch, highlighting the difficulty of securing agentic coding tools, though no in-the-wild exploitation was reported.
What to watch next
- Whether AWS responds about why no CVE was assigned and publishes a full list of affected versions
- Whether the Kiro CLI and Web builds are confirmed to share the same flaw
- Whether users on pre-0.11 versions update, given similar bugs found across AI coding tools like Cursor and Copilot
What changed2
Every report on this story, newest first. Times are when each outlet published.
Coverage2
2 reports
English national1Wire / agency1
Filed from India ×1, United States ×1
Named United States · Amazon · AWS · Kiro · Cymulate · Embrace The Red · HackerOne · Intezer · Johann Rehberger · Kodem Security
- The Hacker NewsAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code[1]English national· neutral

- NVD / CVECVE-2026-10591: Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbi[2]Wire / agency
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.