Amazon Kiro prompt injection can exfiltrate data via Kiro Powers

Mindguard disclosed a prompt injection flaw in Amazon Kiro IDE 0.7.45 on Windows that lets attacker-controlled repository content exfiltrate sensitive local data to an external endpoint. Exploitation requires opening a malicious workspace file and sending any message; no CVE assigned.
Featured · Fergal Glynn
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Agentic Cloud concept introduced
- OpenAI's Codex client reveals GenUI interface platform
- Weaviate 1.39 adds Boost API, MMR, 4-bit quantization
- JPMorgan leads $5B debt package for Volta AI data centers
- Vercel Chat SDK adds Claude Managed Agents and Notion adapter