Find notable cyber news and cases, enriched with sources, timelines, and signals.

Kiro prompt-injection config rewrite RCE remote code execution flaw

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

AWS Kiro had a prompt-injection RCE vulnerability that let hidden web text rewrite ~/.kiro/settings/mcp.json and launch attacker-controlled code on a developer machine. The flaw bypassed Kiro's approval boundary, turning an ordinary URL-fetch or page-summary action into remote code execution with developer privileges. AWS has patched the issue, and the public research included a working proof of concept.

Related Happenings

AWS CodeBuild unanchored pull-request filter misconfiguration security flaw

Vulnerability
H score34 First: 15.01.2026 17:00 Last: 15.01.2026 17:00 Sources 1

About this happening: AWS CodeBuild had an unanchored pull-request filter flaw that let untrusted PRs run privileged builds, creating takeover risk for core AWS GitHub repositories and...

Timeline

  1. 21.07.2026 19:06 1 articles · 4h ago

    Intezer reports a Kiro mcp.json prompt-injection flaw through HackerOne

    Initial Disclosure

    Intezer reported the Kiro mcp.json prompt-injection flaw through HackerOne on February 11, 2026, describing a chain where hidden text on a web page could make Kiro rewrite ~/.kiro/settings/mcp.json and start attacker-controlled code. The company said versions 0.9.2 on macOS and 0.10.16 on Ubuntu were still live when it reported the issue.

    Show sources
  2. 21.07.2026 19:06 2 articles · 4h ago

    AWS ships a Kiro fix for the mcp.json write-to-execution path

    Mitigation Patch Update

    AWS said on April 3, 2026 that a fix for the Kiro mcp.json write-to-execution path had shipped in its latest release. The hardening direction described in the article treats mcp.json and other sensitive files as protected paths that require explicit approval before writes, closing the route used by the prompt-injection chain.

    Show sources
  3. 21.07.2026 19:06 1 articles · 4h ago

    No CVE is assigned and Kiro current builds are on the 1.0.x line

    Untyped Phase

    As of July 21, 2026, no CVE had been assigned to the Kiro mcp.json flaw, AWS had not published a complete list of affected builds, and current Kiro builds were on the 1.0.x line with 1.0.165 listed as the latest release. The article also says users on older versions should update from Kiro's downloads page.

    Show sources