VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_e2642e92805118546c6faf35ce725beb

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Published Aug 27, 2026

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.

The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of

Affected AI Products

prompt injection agentic
Get the weekly digest. Every Monday: top AI security stories of the week. Free.