Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Summary
Amazon Kiro, an AI-powered development environment, has a vulnerability that allows attackers to trick the AI using prompt injection (inserting hidden malicious instructions into input) to steal sensitive data through Kiro Powers (bundles of AI tools and configuration files). The attack requires a user to open a malicious project file and send any message to the AI agent, after which sensitive workspace information can be sent to an attacker's external server without the user's knowledge.
Solution / Mitigation
Following responsible disclosure, a fix for the flaw was implemented by Amazon in Kiro IDE version 0.8.140.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html
First tracked: August 27, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%