Researchers disclosed multiple prompt injection flaws in AWS's Kiro IDE that allowed untrusted content to rewrite the tool's own configuration and execute arbitrary code on a developer's machine. One attack showed that prompt injection hidden in source code comments could modify trusted settings such as .vscode/settings.json or add malicious Model Context Protocol servers through ~/.kiro/settings/mcp.json, effectively allowlisting dangerous Bash commands and triggering local program execution without meaningful user consent.
A later finding showed a poisoned web page could similarly induce Kiro to overwrite its MCP configuration, automatically reload it, and launch attacker-defined MCP servers with the developer's privileges. AWS patched the issues in subsequent Kiro releases, including fixes reported in v0.1.42 and confirmation that the web-based attack no longer worked in v0.11.130, while adding protected-path enforcement and a capability-based permissions model; no CVE was assigned to the reported flaws.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
AWS patched the Kiro flaw that allowed poisoned web content to rewrite MCP configuration and trigger arbitrary code execution, and Intezer confirmed the attack no longer worked in Kiro v0.11.130. No CVE was assigned for this specific finding.
Intezer, working with Kodem Security, found that hidden prompt injection content on a web page could cause AWS Kiro IDE to rewrite ~/.kiro/settings/mcp.json and execute arbitrary code through attacker-defined MCP servers. The finding highlighted Kiro's automatic reload of the file and server launch with the developer's privileges.
AWS reportedly fixed the Kiro issues by releasing version 0.1.42, addressing the ability to alter configuration files and enable malicious command execution paths. No CVE was issued for the vulnerability.
A security researcher notified AWS that Kiro could be abused for arbitrary command execution via indirect prompt injection, including by modifying trusted configuration files such as .vscode/settings.json or .kiro/settings/mcp.json.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceresearch.intezer.com
Open sourceembracethered.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.