Kiro prompt-injection config rewrite RCE remote code execution flaw
Vulnerability
Summary
Hide ▲
Show ▼
AWS Kiro had a prompt-injection RCE vulnerability that let hidden web text rewrite ~/.kiro/settings/mcp.json and launch attacker-controlled code on a developer machine. The flaw bypassed Kiro's approval boundary, turning an ordinary URL-fetch or page-summary action into remote code execution with developer privileges. AWS has patched the issue, and the public research included a working proof of concept.
Related Happenings
AWS CodeBuild unanchored pull-request filter misconfiguration security flaw
Vulnerability
H score34
First: 15.01.2026 17:00
Last: 15.01.2026 17:00
Sources 1
About this happening:
AWS CodeBuild had an unanchored pull-request filter flaw that let untrusted PRs run privileged builds, creating takeover risk for core AWS GitHub repositories and...
AWS CodeBuild unanchored pull-request filter misconfiguration security flaw
VulnerabilityAbout this happening: AWS CodeBuild had an unanchored pull-request filter flaw that let untrusted PRs run privileged builds, creating takeover risk for core AWS GitHub repositories and...
Timeline
-
21.07.2026 19:06 1 articles · 4h ago
Intezer reports a Kiro mcp.json prompt-injection flaw through HackerOne
Initial DisclosureIntezer reported the Kiro mcp.json prompt-injection flaw through HackerOne on February 11, 2026, describing a chain where hidden text on a web page could make Kiro rewrite ~/.kiro/settings/mcp.json and start attacker-controlled code. The company said versions 0.9.2 on macOS and 0.10.16 on Ubuntu were still live when it reported the issue.
Show sources
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code — thehackernews.com — 21.07.2026 19:06
-
21.07.2026 19:06 2 articles · 4h ago
AWS ships a Kiro fix for the mcp.json write-to-execution path
Mitigation Patch UpdateAWS said on April 3, 2026 that a fix for the Kiro mcp.json write-to-execution path had shipped in its latest release. The hardening direction described in the article treats mcp.json and other sensitive files as protected paths that require explicit approval before writes, closing the route used by the prompt-injection chain.
Show sources
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code — thehackernews.com — 21.07.2026 19:06
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code — thehackernews.com — 21.07.2026 19:06
-
21.07.2026 19:06 1 articles · 4h ago
No CVE is assigned and Kiro current builds are on the 1.0.x line
Untyped PhaseAs of July 21, 2026, no CVE had been assigned to the Kiro mcp.json flaw, AWS had not published a complete list of affected builds, and current Kiro builds were on the 1.0.x line with 1.0.165 listed as the latest release. The article also says users on older versions should update from Kiro's downloads page.
Show sources
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code — thehackernews.com — 21.07.2026 19:06