AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Summary
AWS Kiro, an AI coding assistant (agentic IDE, a tool that can autonomously perform coding tasks), had a critical flaw where hidden text on a web page could trick it into rewriting its configuration file and running attacker code on a developer's computer without their approval. The vulnerability worked because Kiro could modify the mcp.json file (which controls which external tools it can load) without requiring developer permission, and it would automatically reload this file and execute whatever tools were listed there.
Solution / Mitigation
AWS has patched the issue. The patch was confirmed in the 0.11 series (as referenced for a related CVE-2026-10591 fix), though the exact patched version number for this specific flaw is not explicitly stated in the source text.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
First tracked: July 21, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%