HackMyIP
← Back to News
2026-08-27 The Hacker News

Amazon Kiro IDE Flaw Enables Silent Data Theft via Prompt Injection

AI SecurityVulnerabilityAI Threats

Cybersecurity researchers at Mindgard have disclosed a prompt injection vulnerability in Amazon Kiro, an AI-powered agentic integrated development environment (IDE), that could allow attackers to silently exfiltrate sensitive local data through a feature called Kiro Powers. The flaw, which has not been assigned a CVE identifier, affects Kiro IDE version 0.7.45 on Windows and was patched by Amazon in version 0.8.140 following responsible disclosure. "The issue allowed attacker-controlled repository content to influence the Kiro agent and ultimately cause sensitive local information to be transmitted to an external endpoint," said Fergal Glynn, Chief Marketing Officer at Mindgard.

Kiro Powers extends standard agent capabilities by bundling Model Context Protocol (MCP) server configurations, steering files ("POWER.md"), hooks, and contextual knowledge. The steering file acts as an "onboarding manual," providing persistent context and instructing the AI agent on which MCP tools are available and when to deploy them. According to Mindgard, exploitation requires two user actions: the target must open a malicious project via File → Open Workspace From File rather than opening the folder directly, and then send any message to the agent. Crucially, the user does not need to submit a malicious prompt or even reference the attacker-controlled content—any message will trigger the vulnerable flow once the crafted workspace file is loaded. The vulnerability is reproducible against both trusted and untrusted workspaces, and exploitation difficulty has been assessed as low.

"The vulnerability appears when attacker-controlled project content is interpreted as instructions, and those instructions are allowed to influence security-sensitive operations elsewhere in the IDE," Mindgard explained. "The trust boundary failure occurs across the entire sequence: repository-controlled content influences the agent, the agent reads sensitive local information, the agent writes that information into security-relevant IDE configuration, and a subsequent IDE capability turns the modified configuration into network activity." Because the exfiltrated traffic blends with normal IDE behavior, users concerned about outbound connections can audit their setup using our DNS leak test or SSL/TLS checker to verify which endpoints their development tools are communicating with.

The disclosure underscores a growing class of risk in AI-assisted development environments, where interpretation and execution are increasingly merged within the same workflow. An Amazon spokesperson confirmed the fix to The Hacker News, stating, "We addressed this finding, in the January 15 Kiro IDE update, shortly after it was reported to us. As always, we recommend customers keep their software up to date." Developers using Kiro or similar agentic IDEs should update immediately and review workspace handling practices. A broader privacy checkup can help teams audit how AI tools handle local files and outbound data flows.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →