Threat · curated 19 Aug 2026

Amazon Kiro: AI Is Breaking Vulnerability Disclosure Processes

Dossier

Coverage timeline

discovered mindgard.ai primary 19 Aug 2026cymulate.comthehackernews.comdarkreading.com 2 Sep 2026thehackernews.comnsfocusglobal.comamazon.com

Why it matters

Amazon Kiro's flaw shows how untrusted repository content can weaponize an agentic coding assistant into an automatic data-exfiltration channel, a growing risk as developers adopt AI IDEs with tool and MCP access.

Mindgard disclosed a prompt-injection vulnerability in Amazon Kiro, an agentic AI-powered IDE, that allows attacker-controlled repository content to influence the Kiro agent via Kiro Powers (including steering files and MCP configurations) and exfiltrate sensitive local data to an external endpoint. Tested against Kiro IDE 0.7.45 on Windows, the demonstrated flow causes the agent to read secrets, modify a workspace URL, and trigger an outbound request without the user explicitly requesting the data access; exploitation requires opening a malicious workspace file and sending a message to the agent.

vuln-research

Summary

Mindgard disclosed a data-exfiltration vulnerability in Amazon Kiro, an AI-powered agentic integrated development environment, that abuses prompt injection and the Kiro Powers feature. Attacker-controlled repository content is interpreted as instructions and allowed to influence security-sensitive operations, ultimately causing sensitive local information to be transmitted to an external endpoint without the user explicitly requesting it. The flaw has no CVE identifier and was tested against Kiro IDE 0.7.45 on Windows, reproducing in both trusted and untrusted workspaces.[0][2][14]

Exploitation requires only two low-effort user actions: opening a malicious project via File → Open Workspace From File and then sending any message to the agent. Notably, the user need not submit a malicious prompt or reference the attacker content — sending any message triggers the vulnerable flow — and exploitation difficulty is assessed as low. Mindgard describes the root cause as a trust boundary failure spanning the whole sequence, where repository content influences the agent, the agent reads sensitive local data and writes it into security-relevant IDE configuration, and a later IDE capability converts that configuration into outbound network activity.[0][14]

Following responsible disclosure, Amazon fixed the flaw in Kiro IDE version 0.8.140 in its January 15 update. The finding builds on an earlier Mindgard steering-file exfiltration bug (initially classified as a duplicate) and follows a separate June 2026 Kiro flaw, CVE-2026-10591 (CVSS 8.8), an insufficient access control issue enabling remote arbitrary command execution. There is no evidence of in-the-wild exploitation; the research doubles as a critique of how AI-tool vulnerability disclosure processes struggle to evaluate multi-step agentic execution paths.[0][14]

Attack chain

  1. Delivery via malicious workspace: An attacker crafts repository content, including Kiro Powers artifacts such as a steering file, and induces the victim to open the malicious project through a workspace file using File → Open Workspace From File rather than opening the folder directly.[0][14]
  2. Trigger via any agent message: After the workspace is opened, the user simply sends any message to the Kiro agent — no malicious prompt or reference to the attacker content is required — which starts the vulnerable flow.[0]
  3. Interpretation and local data access: The attacker-controlled project content is interpreted as instructions that influence the agent, causing Kiro to read sensitive local information.[0]
  4. Configuration poisoning and exfiltration: The agent writes the sensitive information into security-relevant IDE configuration, and a subsequent IDE capability turns the modified configuration into network activity, transmitting the data to an external endpoint.[0]

Disclosure timeline

DateEvent
June 2026Amazon addressed a separate Kiro insufficient access control flaw, CVE-2026-10591 (CVSS 8.8), enabling remote unauthenticated arbitrary command execution via writes to execution-sensitive paths and auto-execution on folder open.[0][20]
January 15Amazon implemented a fix for the prompt-injection data-exfiltration finding in Kiro IDE version 0.8.140, shortly after it was reported.[0]
August 14, 2026Mindgard published its blog detailing the Kiro Powers prompt-injection data-exfiltration vulnerability.[14]
August 27, 2026Coverage and the Mindgard blog were updated to include Amazon's response.[0][14]

How it works

The vulnerability arises when attacker-controlled project content is interpreted as instructions and those instructions are allowed to influence security-sensitive operations elsewhere in the IDE. Mindgard describes a trust boundary failure across the entire sequence: repository-controlled content influences the Kiro agent, the agent reads sensitive local information, the agent writes that information into security-relevant IDE configuration, and a subsequent IDE capability turns the modified configuration into network activity that reaches an external endpoint.[0]

Kiro Powers extends agent skills by bundling Model Context Protocol (MCP) server configurations, steering files (POWER.md), hooks, and contextual knowledge. The steering file acts as an onboarding manual that gives the agent persistent context and tells it which MCP tools are available and when to use them, providing the persistent-instruction surface that attacker-controlled content abuses.[0]

The exploitation flow is triggered by two ordinary user actions — opening the malicious project via File → Open Workspace From File and sending any message — after which sensitive workspace data is exfiltrated without the user requesting Kiro access or transmit it. The finding builds on a prior Mindgard technique in which a steering file was crafted to read a local file and render a Markdown image, coercing the AI to send sensitive data to an external server.[0][19]

Affected versions and patch status

ProductAffectedPatch status
Amazon Kiro IDE (Windows)Version 0.7.45 (tested); reproducible in both trusted and untrusted workspacesFixed in Kiro IDE version 0.8.140 (January 15 update); latest version is 1.0.337[0][14]

Indicators of Compromise

TypeIndicatorContext
cveCVE-2026-10591Separate June 2026 Amazon Kiro insufficient access control flaw (CVSS 8.8) referenced as prior context; enabled remote arbitrary command execution via crafted instructions.[0][20]
file-path.vscode/tasks.jsonExecution-sensitive path cited for CVE-2026-10591 that crafted instructions could write to, facilitating auto-execution on folder open in Kiro.[0]
file-path~/.kiro/settings/mcp.jsonKiro MCP server configuration path cited for CVE-2026-10591 that malicious writes could target to gain code execution.[0]

Key takeaways

  • In agentic AI IDEs like Kiro, attacker-controlled repository content can be interpreted as instructions and influence security-sensitive operations, so sensitive local data can be exfiltrated after merely opening a crafted workspace file and sending any message — no malicious prompt required.[0]
  • The trust boundary failure is a multi-step chain (content influences agent, agent reads local data, agent writes IDE configuration, IDE capability produces network traffic), and this class of AI vulnerability is difficult to evaluate with disclosure processes built around clearly defined software defects.[0][14]
  • Kiro has now accumulated multiple prompt-injection-driven security findings — the Kiro Powers exfiltration flaw (fixed in 0.8.140), an earlier steering-file exfiltration bug, and CVE-2026-10591 — underscoring that combining model interpretation with tool execution reintroduces systemic risk across AI development tools.[0][14]

Defensive actions

  • Upgrade Kiro IDE to the latest version (at least 0.8.140, ideally 1.0.337).: Amazon fixed the prompt-injection data-exfiltration flaw in 0.8.140 and recommends installing the latest version to receive security updates.[0]
  • Avoid opening untrusted projects through workspace files (File → Open Workspace From File) and treat repository content as potentially instruction-bearing to an agentic IDE.: Exploitation requires opening the malicious project via the workspace-file path and then sending any message; the attacker content is interpreted as agent instructions regardless of workspace trust designation.[0][14]