AWS Patches Kiro Prompt-Injection Flaw Enabling Arbitrary Code Execution
Amazon Web Services’ Kiro is an agentic development environment designed to help programmers inspect projects, modify files and invoke external tools. Because such AI agents can interact directly with local resources, user-approval controls are a critical boundary against untrusted instructions. A failure in that boundary can turn prompt injection — often treated as a content-manipulation problem — into a broader endpoint and software supply-chain risk.
Security researchers found that attackers could conceal malicious instructions in a webpage and manipulate Kiro into rewriting Model Context Protocol, or MCP, server configurations. The technique could bypass the product’s approval process and lead to arbitrary code execution on a developer’s local machine. AWS has released an updated version to address the vulnerability. As of July 22, 2026, users should install the latest official build and review MCP settings for unauthorized changes.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.