Back to IntelRead Original Source
Intel Node
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
lowadvisory2026-07-21T16:06:12+00:00source excerpt
cloud
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution.