← Back to Tech & Science

AWS Kiro IDE Flaw Allows Malicious Code Execution via Prompt Injection

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SEATTLE — A critical vulnerability in Amazon Web Services' new agentic coding tool, AWS Kiro, allows attackers to execute malicious code with developer-level privileges by exploiting a flaw in the system's safety model. Researchers from Intezer and Kodem Security disclosed the issue on Monday, warning that poisoned web pages can trick the artificial intelligence into rewriting configuration files without user approval.

The vulnerability stems from an oversight in AWS Kiro's security boundaries. The tool is designed to assist developers by autonomously writing code based on natural language prompts. However, Intezer and Kodem Security found that if a developer visits a malicious website while using the IDE, the site can inject crafted text into the AI agent's context window. This prompt injection bypasses the safety model intended to prevent unauthorized file system access.

Once triggered, the compromised agent gains the ability to write directly to configuration files and execute arbitrary code within the user's development environment. Because the tool operates with elevated permissions necessary for its function, successful exploitation grants an attacker full control over the developer's local machine or connected cloud resources. The flaw effectively allows remote attackers to pivot from a simple web browsing session into a high-privilege compromise of sensitive infrastructure.

AWS Kiro was released earlier this year as part of Amazon's push toward autonomous software development agents, promising to streamline coding workflows by reducing manual intervention. The discovery highlights the risks inherent in granting AI systems broad file system access without granular approval mechanisms for every action. Security experts note that while traditional code editors require explicit user confirmation before overwriting files or running scripts, agentic tools like Kiro are designed to act autonomously based on inferred intent.

The researchers stated they notified AWS of the vulnerability prior to public disclosure. In response, Amazon acknowledged the issue and is working on a patch for affected users. The company has not yet specified whether any known attacks have exploited this flaw in the wild or if customer data was compromised during the window between discovery and notification.

As developers increasingly rely on AI agents to manage complex coding tasks, incidents like this underscore the difficulty of securing systems where the boundary between user input and system execution is blurred. The incident raises questions about how cloud providers will balance the convenience of autonomous tools with the need for strict security controls in a rapidly evolving threat landscape.

Amazon has advised users running AWS Kiro to limit network access within their development environments until an official update is deployed. Security teams are monitoring for signs of exploitation, but no widespread attacks have been confirmed as of Monday afternoon.

Discussion

0 / 2000