YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0054

Incident record

AWS Kiro agentic IDE flaw let a poisoned web page rewrite its config and run code

Severity
High
Status
Patched
Type
Prompt Injection
Target
AWS Kiro
Actor
researcher
CVE
CVE-2026-10591

What happened

Researchers at Intezer and Kodem Security disclosed a flaw in AWS's Kiro agentic IDE in which hidden instructions on a web page could make the agent rewrite its Model Context Protocol configuration and gain code execution with the developer's privileges. The developer approves only the page fetch; the configuration rewrite then needs no approval, because the settings file is not protected against the agent's own file-write tool. AWS deployed a fix on 3 April 2026 without naming a version, and Intezer confirmed the flaw patched in Kiro v0.11.130. It was demonstrated as a proof-of-concept with no reported in-the-wild exploitation.

Amazon assigned CVE-2026-10591 to the finding on 22 July 2026. The public record for that identifier is broader than this research: AWS security bulletin 2026-037, published 2 June 2026, is titled 'Kiro IDE insufficient file write restrictions to execution-sensitive paths', covers writes to paths such as .vscode/tasks.json, says the fix landed in Kiro 0.11, and credits Cymulate rather than Intezer or Kodem. Amazon folded the configuration-rewrite variant into the same identifier.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026