importantSYS.SOURCE: The Hacker News• 2026-08-27T19:09:56+05:30
Amazon Kiro Prompt Injection Vulnerability Enables Sensitive Data Exfiltration via Kiro Powers
A prompt injection vulnerability in Amazon Kiro IDE allows sensitive data exfiltration through Kiro Powers without user interaction, with a fix released in version 0.8.140. The flaw leverages workspace files to manipulate the AI agent's behavior and transmit local information to external endpoints.
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.
The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of
*** END OF TRANSMISSION ***