Security · 4h ago
AWS Kiro IDE Flaw Allowed RCE via Poisoned Web Page
A vulnerability in AWS's Kiro coding IDE let a malicious web page rewrite its config and execute code without user approval. Intezer and Kodem Security discovered that asking Kiro to summarize a page could trigger remote code execution. AWS has patched the issue; no CVE was assigned.
Meridian48 take
The flaw underscores the risks of agentic AI tools that act on user requests without robust sandboxing, even from trusted vendors.
Read the full reporting
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code →
The Hacker News
aws-kiroremote-code-execution