Tools AI Risk Radar ai-incident-0054
Incident record
AWS Kiro agentic IDE flaw let a poisoned web page rewrite its config and run code
- Severity
- High
- Status
- Patched
- Type
- Prompt Injection
- Target
- AWS Kiro
- Actor
- researcher
- CVE
- CVE-2026-10591
What happened
Researchers at Intezer and Kodem Security disclosed a flaw in AWS's Kiro agentic IDE in which hidden instructions on a web page could make the agent rewrite its Model Context Protocol configuration and gain code execution with the developer's privileges. The developer approves only the page fetch; the configuration rewrite then needs no approval, because the settings file is not protected against the agent's own file-write tool. AWS deployed a fix on 3 April 2026 without naming a version, and Intezer confirmed the flaw patched in Kiro v0.11.130. It was demonstrated as a proof-of-concept with no reported in-the-wild exploitation.
Amazon assigned CVE-2026-10591 to the finding on 22 July 2026. The public record for that identifier is broader than this research: AWS security bulletin 2026-037, published 2 June 2026, is titled 'Kiro IDE insufficient file write restrictions to execution-sensitive paths', covers writes to paths such as .vscode/tasks.json, says the fix landed in Kiro 0.11, and credits Cymulate rather than Intezer or Kodem. Amazon folded the configuration-rewrite variant into the same identifier.
Sources
- Intezer: remote code execution in AWS Kiro through a poisoned web page (20 July 2026)research.intezer.com/blog/2026/07/remote-code-execution-kiro…
- AWS security bulletin 2026-037: Kiro IDE insufficient file write restrictions to execution-sensitive paths (2 June 2026)aws.amazon.com/security/security-bulletins/2026-037-aws/
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026