Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
AdvisoryAmazonOur summary
Researchers disclosed a vulnerability in Amazon's Kiro IDE that allows attackers to steal sensitive local data through prompt injection and the IDE's 'Kiro Powers' feature. The flaw, which affects version 0.7.45 on Windows, enables malicious repository content to manipulate the AI agent into transmitting information to external endpoints without explicit user consent. Amazon has resolved the issue in version 0.8.140, though users of older versions remain exposed to this low-difficulty exploitation path.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.