AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Hidden text on a web page could trick AWS Kiro into rewriting its own MCP configuration and executing attacker-controlled code on a developer’s machine, bypassing the normal approval flow. AWS has patched the flaw in newer releases, with Intezer confirming the issue was fixed in v0.11.130 and noting no CVE was assigned. #Kiro #AWS #Intezer #KodemSecurity #mcp.json

Keypoints

  • Hidden text in a web page triggered prompt injection in Kiro.
  • Kiro could rewrite mcp.json without approval and reload it automatically.
  • The malicious MCP entry could launch arbitrary code with developer privileges.
  • AWS patched the issue by protecting sensitive paths like mcp.json and .git.
  • Intezer confirmed the attack failed in v0.11.130, and no CVE was assigned.

Read More: https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html