AWS Kiro Vulnerability Allows Remote Code Execution via Hidden Web Text

AWS Kiro Vulnerability Allows Remote Code Execution via Hidden Web Text

First seen 23 Jul 2026, 01:23 UTC ThehackernewsTechtimesCybersecuritynewsembracethered.comresearch.intezer.com 81% similarity 67.5

Article Content

Browse articles
ThreatCluster

A vulnerability in AWS Kiro, an AI-powered IDE, was disclosed on July 21, 2026, allowing attackers to execute code on a developer's machine through a hidden line of text on a webpage. The flaw bypasses Kiro's 'human-in-the-loop' security model, which is supposed to require user approval for executing shell commands. Intezer and Kodem Security discovered that Kiro could rewrite its configuration file without triggering any approval dialog, enabling remote code execution. The vulnerability affects all versions of Kiro prior to v0.11.130, which was released months ago. AWS has patched the flaw, but no CVE has been assigned, meaning many developers may remain unaware of their vulnerability. The attack method involved embedding invisible text in HTML, which Kiro read when fetching a URL, leading to the execution of arbitrary code. This incident raises significant concerns about the security of AI-powered development tools.

Key Points: • AWS Kiro's vulnerability allows remote code execution via hidden text on web pages. • The flaw bypasses Kiro's security model, which should require user approval for actions. • No CVE has been assigned, leaving many developers unaware of their exposure.

ThreatCluster AI

Timeline

2026-02-01
Coordinated disclosure process began
Intezer and Kodem Security started disclosing the vulnerability to AWS, leading to a five-month process.
Techtimes
2026-06-02
CVE-2026-10591 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
Vulnerability disclosed
Intezer and Kodem Security publicly revealed the vulnerability in AWS Kiro, detailing the attack method.
Techtimes
2026-07-22
AWS patched Kiro
AWS released a patch for Kiro, addressing the vulnerability in version v0.11.130.
Techtimes

Community

Browse all →