Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AWS Kiro Vulnerability Exposed Code Execution Risk

AWS Kiro Vulnerability Exposed Code Execution Risk

Posted on July 21, 2026 By CWS

A recent security flaw in AWS’s Kiro coding IDE allowed malicious actors to execute code on developers’ machines without their consent. This vulnerability, identified by Intezer and Kodem Security, involved Kiro rewriting its configuration file and executing external code based on hidden text embedded in a web page. Although AWS has addressed the issue, it highlights significant security concerns in software development environments.

Remote Code Execution via Hidden Text

The flaw was related to Kiro’s handling of external content. Researchers found that when Kiro was asked to summarize a webpage, it could inadvertently run remote code. This happened because the agent’s safety model relied on user approval, which the exploit managed to bypass. By embedding instructions in barely visible text within a webpage, attackers could manipulate Kiro’s settings and execute arbitrary code.

The vulnerability stemmed from Kiro’s configuration file at ~/.kiro/settings/mcp.json, which dictates the external tools the IDE can load. If an attacker altered this file, Kiro would automatically reload it, launching potentially harmful code with the developer’s privileges. This issue was compounded by Kiro’s ability to modify this file autonomously without seeking user approval.

Implications and Past Vulnerabilities

The implications of this vulnerability are severe, as it allows attackers to gain unauthorized access to sensitive information and execute harmful commands. Intezer’s demonstration showed how the exploit could be used to extract system details, but it could also be extended to steal credentials or access internal systems. Although AWS has released patches, the flaw was live in specific versions of Kiro at the time of discovery.

This is not the first time Kiro has faced such vulnerabilities. Previous iterations allowed similar exploits, where the IDE would execute code from altered configuration files without proper user consent. AWS attempted to mitigate these issues by introducing approval prompts, but gaps remained, particularly in the Autopilot mode.

Resolution and Future Outlook

AWS has responded by updating Kiro to prevent unauthorized changes to its configuration files, now requiring explicit user approval for any modifications. The update also introduces a protected-paths system to safeguard critical files, marking a shift towards a more secure development environment. This approach ensures that even if the model is compromised, the platform enforces necessary security checks.

Despite the absence of a CVE assignment for this vulnerability, AWS has urged users to update to the latest Kiro version. The ongoing discovery of vulnerabilities in AI-driven coding tools underscores the need for robust platform-level security measures. As development workflows increasingly rely on automated systems, ensuring these systems are secure remains a top priority.

The Hacker News continues to seek clarification from AWS regarding the affected versions and the decision not to assign a CVE. Meanwhile, developers are encouraged to update their IDEs to avoid potential security risks.

The Hacker News Tags:AWS, cloud computing, code execution, CVE, Cybersecurity, developer tools, HackerOne, IDE security, Intezer, IT security, Kiro, security flaw, software patch, software update, Vulnerability

Post navigation

Previous Post: Critical Security Flaw in SharePoint Poses Major Threat
Next Post: Zimbra Releases Critical Security Patches for Vulnerabilities

Related Posts

Weekly Security Highlights: AI Breaches, Bitcoin Heist, and More Weekly Security Highlights: AI Breaches, Bitcoin Heist, and More The Hacker News
New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack The Hacker News
Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL The Hacker News
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts The Hacker News
AI Finds 21 Zero-Day Bugs in FFmpeg; Chrome Fixes 429 Issues AI Finds 21 Zero-Day Bugs in FFmpeg; Chrome Fixes 429 Issues The Hacker News
Microsoft 365 Android Apps Vulnerability Allows Token Theft Microsoft 365 Android Apps Vulnerability Allows Token Theft The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark