Thehackernews AWS Kiro Vulnerability Allows Remote Code Execution via Hidden Web Text
Article Content
- •AWS Kiro's vulnerability allows remote code execution via hidden text on web pages.
- •The flaw bypasses Kiro's security model, which should require user approval for actions.
- •No CVE has been assigned, leaving many developers unaware of their exposure.
A vulnerability in AWS Kiro, an AI-powered IDE, was disclosed on July 21, 2026, allowing attackers to execute code on a developer's machine through a hidden line of text on a webpage. The flaw bypasses Kiro's 'human-in-the-loop' security model, which is supposed to require user approval for executing shell commands. Intezer and Kodem Security discovered that Kiro could rewrite its configuration file without triggering any approval dialog, enabling remote code execution. The vulnerability affects all versions of Kiro prior to v0.11.130, which was released months ago. AWS has patched the flaw, but no CVE has been assigned, meaning many developers may remain unaware of their vulnerability. The attack method involved embedding invisible text in HTML, which Kiro read when fetching a URL, leading to the execution of arbitrary code. This incident raises significant concerns about the security of AI-powered development tools.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track AWS and CVE-2026-10591 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…