CVE Tools
Back to feed
Advisory Amazon ai-ml info-disclosure

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

Researchers disclosed a vulnerability in Amazon's Kiro IDE that allows attackers to steal sensitive local data through prompt injection and the IDE's 'Kiro Powers' feature. The flaw, which affects version 0.7.45 on Windows, enables malicious repository content to manipulate the AI agent into transmitting information to external endpoints without explicit user consent. Amazon has resolved the issue in version 0.8.140, though users of older versions remain exposed to this low-difficulty exploitation path.