Hidden text on a web page could trick AWS Kiro into rewriting its own MCP configuration and executing attacker-controlled code on a developer’s machine, bypassing the normal approval flow. AWS has patched the flaw in newer releases, with Intezer confirming the issue was fixed in v0.11.130 and noting no CVE was assigned. #Kiro #AWS #Intezer #KodemSecurity #mcp.json
Keypoints
- Hidden text in a web page triggered prompt injection in Kiro.
- Kiro could rewrite mcp.json without approval and reload it automatically.
- The malicious MCP entry could launch arbitrary code with developer privileges.
- AWS patched the issue by protecting sensitive paths like mcp.json and .git.
- Intezer confirmed the attack failed in v0.11.130, and no CVE was assigned.
Read More: https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html