AnalysisCybersecurityAugust 27, 2026

Amazon Kiro prompt injection can exfiltrate data via Kiro Powers

Mindguard disclosed a prompt injection flaw in Amazon Kiro IDE 0.7.45 on Windows that lets attacker-controlled repository content exfiltrate sensitive local data to an external endpoint. Exploitation requires opening a malicious workspace file and sending any message; no CVE assigned.

Featured · Fergal Glynn

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed
Amazon Kiro prompt injection can exfiltrate data via Kiro Powers — AIBriefs