CVE Tools
Back to feed
Research Kiro rce AWS mobile

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

A critical vulnerability in AWS's Kiro coding IDE allowed attackers to exploit a poisoned web page to rewrite configuration files and execute arbitrary code on a developer's machine. The flaw bypassed Kiro’s approval-based security model, enabling unauthorized actions without user interaction. Researchers from Intezer and Kodem Security discovered that manipulating the mcp.json file—used to define external tools—could lead to remote code execution. AWS has since patched the issue, but no CVE identifier was assigned. The vulnerability affected versions up to 0.10.16 and was confirmed resolved in version 0.11.130. Developers are advised to update to the latest stable release to ensure protection.