#10
The Hacker News
general
July 21, 2026 at 16:06 UTC
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
By [email protected] (The Hacker News)
AI Summary
A prompt injection vulnerability in AWS Kiro, Amazon's agentic coding IDE, allowed a poisoned web page to instruct Kiro to rewrite its own configuration file and execute arbitrary attacker-controlled code on the developer's machine with no approval step able to block it. Discovered jointly by Intezer and Kodem Security, AWS patched the issue with no CVE assigned. The attack required nothing more than asking Kiro to summarize a malicious page, illustrating the RCE risk inherent in agentic AI development tools.
Relevance score: 81.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →