Thehackernews
AWS Kiro Vulnerability Allows Remote Code Execution via Hidden Web Text
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A vulnerability in AWS Kiro, an AI-powered IDE, was disclosed on July 21, 2026, allowing attackers to execute code on a developer's machine through a hidden line of text on a webpage. The flaw bypasses Kiro's 'human-in-the-loop' security model, which is supposed to require user approval for executing shell commands. Intezer and Kodem Security discovered that Kiro could rewrite its configuration file without triggering any approval dialog, enabling remote code execution. The vulnerability affects all versions of Kiro prior to v0.11.130, which was released months ago. AWS has patched the flaw, but no CVE has been assigned, meaning many developers may remain unaware of their vulnerability. The attack method involved embedding invisible text in HTML, which Kiro read when fetching a URL, leading to the execution of arbitrary code. This incident raises significant concerns about the security of AI-powered development tools.
Key Points: • AWS Kiro's vulnerability allows remote code execution via hidden text on web pages. • The flaw bypasses Kiro's security model, which should require user approval for actions. • No CVE has been assigned, leaving many developers unaware of their exposure.