Research Kiro rce AWS mobile
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
CVE Tools coverage
A critical vulnerability in AWS's Kiro coding IDE allowed attackers to exploit a poisoned web page to rewrite configuration files and execute arbitrary code on a developer's machine. The flaw bypassed Kiro’s approval-based security model, enabling unauthorized actions without user interaction. Researchers from Intezer and Kodem Security discovered that manipulating the mcp.json file—used to define external tools—could lead to remote code execution. AWS has since patched the issue, but no CVE identifier was assigned. The vulnerability affected versions up to 0.10.16 and was confirmed resolved in version 0.11.130. Developers are advised to update to the latest stable release to ensure protection.