By Interestana AI Editorial — AI-drafted, human-overseen. How we report
AWS Kiro Vulnerability Allowed Code Execution Via Web Page

A critical vulnerability in Amazon Web Services' (AWS) agentic coding IDE, Kiro, allowed a specially crafted web page to rewrite the IDE's configuration file and execute arbitrary code on a developer's machine. Intezer, in research conducted with Kodem Security, discovered that a seemingly innocuous request, such as asking Kiro to summarize a web page, could trigger this exploit. The vulnerability bypassed any approval steps, meaning the malicious code could run without user intervention. This allowed for remote code execution on the developer's system.
AWS has since addressed the security flaw, issuing a patch to rectify the issue. The vulnerability was identified as a significant risk because it leveraged the IDE's functionality to manipulate its own settings and execute commands. The research highlighted that the attack vector involved embedding hidden text within a web page, which Kiro would then process. This processing led to the modification of Kiro's configuration, enabling the execution of code controlled by an attacker. No CVE identifier has been assigned to this vulnerability as of the reporting.
The discovery underscores the potential risks associated with agentic tools that interact with external web content and possess the ability to modify their own operational parameters. The lack of an explicit approval mechanism for such modifications proved to be the critical weakness exploited. Developers using Kiro were potentially exposed to the risk of their systems being compromised through this method. The swift patching by AWS aims to mitigate any ongoing threat posed by this specific flaw.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.