Mindgard disclosed a prompt-injection flaw in Amazon Kiro IDE that allowed a malicious repository opened through a workspace file to be treated as agent instructions after a user sent any message. In testing against Kiro 0.7.45 for Windows, the agent could read local secrets, alter workspace configuration, and use Kiro Powers network capabilities to exfiltrate data, reportedly without approval prompts in either trusted or untrusted workspace modes.
The issue stemmed from inadequate trust separation between repository content, agent tool permissions, writable IDE configuration, and outbound network access. Mindgard reported the vulnerability to Amazon in December 2025; Amazon remediated it in January 2026 and shipped the fix in Kiro 0.8.140. The disclosure, alongside reporting on excessive IAM privilege risks in AWS AgentCore deployments, reinforces that AI-agent integrations require strict least-privilege controls and explicit approval gates for secret access and network actions.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Mindgard publicly disclosed the Amazon Kiro IDE prompt-injection vulnerability, describing exfiltration through attacker-controlled workspace configuration and legitimate Kiro Powers network requests. No CVE had been assigned at the time of disclosure.
Amazon patched CVE-2026-10591, a Kiro vulnerability with a CVSS score of 8.8 that permitted writes to sensitive paths including .vscode/tasks.json and ~/.kiro/settings/mcp.json.
Intezer demonstrated that a poisoned webpage could cause Kiro to modify ~/.kiro/settings/mcp.json, leading to remote code execution.
Amazon completed remediation for the reported Kiro prompt-injection vulnerability and released the fix in Kiro version 0.8.140.
Mindgard reported a prompt-injection vulnerability to Amazon in which a malicious Kiro workspace and repository content could steer the agent to read local secrets, alter configuration, and exfiltrate data through Kiro Powers networking.
Mindgard identified an earlier Kiro steering-file variant that could induce the agent to append local file contents to Markdown image URLs for exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.