Mark RadarMARK RADAR
EN

AWS Patches Kiro Prompt-Injection Flaw Enabling Arbitrary Code Execution

1 reports · First detected 2026-07-22 · Last active 2026-07-22

Amazon Web Services’ Kiro is an agentic development environment designed to help programmers inspect projects, modify files and invoke external tools. Because such AI agents can interact directly with local resources, user-approval controls are a critical boundary against untrusted instructions. A failure in that boundary can turn prompt injection — often treated as a content-manipulation problem — into a broader endpoint and software supply-chain risk.

Security researchers found that attackers could conceal malicious instructions in a webpage and manipulate Kiro into rewriting Model Context Protocol, or MCP, server configurations. The technique could bypass the product’s approval process and lead to arbitrary code execution on a developer’s local machine. AWS has released an updated version to address the vulnerability. As of July 22, 2026, users should install the latest official build and review MCP settings for unauthorized changes.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)