Researchers Disclose Prompt Injection Vulnerability In Amazon Kiro IDE

Published:

Cybersecurity researchers have disclosed a security vulnerability in Amazon Kiro, an artificial intelligence powered integrated development environment, that could enable attackers to exfiltrate sensitive local information through prompt injection and the platform’s Kiro Powers functionality. The issue, identified by security researchers at Mindgard, affected Kiro IDE version 0.7.45 on Windows and did not receive a CVE identifier. According to the researchers, the flaw allowed attacker controlled repository content to influence the AI agent and ultimately transmit sensitive local data to an external destination. Amazon has since addressed the issue in Kiro IDE version 0.8.140 following responsible disclosure. The findings highlight the growing security challenges associated with AI powered development environments that combine language models with automation capabilities capable of interacting with local systems.

Kiro Powers extends the functionality of the development environment by combining Model Context Protocol server configurations, steering files, hooks, and contextual knowledge that provide persistent instructions to the AI agent. Mindgard explained that exploitation requires two user actions. A developer must first open a specially crafted project using the “Open Workspace From File” option instead of opening the folder directly and then send any message to the AI assistant. Once these conditions are met, the attack can proceed without requiring the user to reference malicious content or intentionally request access to sensitive files. Researchers stated that the vulnerability stems from repository controlled content being interpreted as trusted instructions, allowing the AI agent to access sensitive local information, modify security relevant IDE configurations, and trigger network activity that results in data being transmitted externally. The researchers assessed the exploitation difficulty as low and noted that the issue affects both trusted and untrusted workspaces.

Mindgard said the vulnerability reflects a broader trust boundary failure that can occur when AI agents interpret repository content while also being granted access to files, tools, and application settings. According to the report, repository supplied instructions can influence the AI model, which then reads local information and writes it into configuration files that later trigger network communication. The researchers explained that this interaction between model interpretation and application logic creates new attack paths that traditional software security models do not fully address. The disclosed vulnerability also builds upon a previously identified issue in Kiro where steering file directives could embed sensitive local information into Markdown image requests sent to external servers. Earlier this year, Amazon also resolved another Kiro vulnerability, tracked as CVE 2026 10591, involving insufficient access controls that could allow remote command execution through crafted instructions targeting execution sensitive configuration files.

The disclosure comes as researchers continue identifying security weaknesses across AI development tools used by software engineers. Recent studies have reported vulnerabilities affecting products including OpenAI Codex CLI, Cursor, GitHub Copilot CLI, Google Gemini CLI, Anthropic Claude Code, NVIDIA NemoClaw, OpenClaw, Microsoft Visual Studio Code MCP functionality, and Claude Desktop. These issues include prompt injection, sandbox escapes, remote code execution, privilege escalation, and configuration manipulation that can lead to unauthorized access or execution of attacker controlled commands. Mindgard stated that the Amazon Kiro findings demonstrate how AI vulnerabilities increasingly arise from complex interactions between language models, application logic, external resources, and integrated tools rather than traditional software flaws alone. The researchers emphasized that as AI assistants continue gaining broader access to development environments and system resources, vulnerability assessment and disclosure processes will need to evolve to evaluate these complex execution paths with the same level of detail applied to conventional software security testing.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img