Amazon’s Kiro IDE leaks data when poisoned projects get opened

A prompt injection flaw in Amazon's Kiro IDE can push sensitive local data to attackers when a poisoned project is opened.

CSBadmin
2 Min Read

Mindgard has disclosed a prompt injection vulnerability in Amazon Kiro, the AI-powered agentic IDE, that lets attacker-controlled repository content push sensitive local data out of the developer’s machine.

No CVE was assigned. Mindgard confirmed the issue in Kiro IDE 0.7.45 on Windows; the current build is 1.0.337. Exploitation is rated low difficulty and requires two user actions: opening a malicious project through File, then Open Workspace From File rather than opening the folder directly, and sending any message to the agent. No malicious prompt is needed.

Once the crafted workspace file is opened, sending any message is enough to trigger the vulnerable flow, the researchers said. Kiro Powers bundle MCP server configurations, steering files, hooks, and contextual knowledge, and the steering file acts as an onboarding manual that tells the agent what tools exist and when to use them.

The chain crosses several trust boundaries: repository content is interpreted as instructions, the agent reads sensitive local information, writes it into security-relevant IDE configuration, and a subsequent IDE capability converts that configuration into network activity.

Amazon shipped the remedy in Kiro IDE 0.8.140, published on January 15. It follows a June patch for CVE-2026-10591 (CVSS 8.8), an insufficient access control flaw that allowed remote code execution through crafted instructions, and a wave of similar findings across Codex CLI, Cursor, Gemini CLI, and Claude Code.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.